CVE-2020-1056 is an elevation of privilege vulnerability in Microsoft Edge caused by improper enforcement of cross-domain policies. The flaw allows attacker-controlled web content to access information from one domain and inject it into another domain, violating intended browser origin isolation boundaries. Exploitation occurs in a web-based attack scenario in which a user is persuaded to visit malicious or compromised content crafted to trigger the policy enforcement failure. The vulnerability is addressed by correcting how Microsoft Edge enforces cross-domain restrictions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone proof-of-concept exploit for CVE-2020-10567 affecting Responsive Filemanager v9.14.0. It contains two files: a Python exploit script and a README with usage examples. The Python script is the main entry point and uses the requests library to interact with the vulnerable web application. Exploit flow: the script accepts a target base URL, an arbitrary command to run, and optionally a PHPSESSID cookie. If no cookie is provided, it performs a GET request to /filemanager/dialog.php to collect a session cookie. It then builds a PHP payload containing shell_exec('<command>'), base64-encodes it, and submits it to /filemanager/ajax_calls.php?action=save_img using a data URI beginning with data:image/jpeg;base64,. The POST body sets the uploaded filename to shell.php. After upload, the script requests /source/shell.php, which executes the embedded command on the server and returns the output in the HTTP response body. The exploit’s main capability is unauthenticated remote code execution through arbitrary file upload and subsequent execution of the uploaded PHP file. It is not merely a detector; it actively weaponizes the vulnerability by planting a webshell-like PHP script. The payload is basic and hardcoded to a single command per run, so the maturity is best classified as OPERATIONAL rather than framework-grade weaponized. Repository structure is minimal: README.md documents the vulnerability, states that no authentication is required, and provides example invocations showing command execution such as id and cat /etc/passwd. There is no framework integration, no persistence logic beyond leaving shell.php on the server, and no cleanup routine. The code is concise and purpose-built to demonstrate exploitation of the vulnerable save_img handler and retrieval of command output.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.