← Volver al buscador de CVEs

CVE-2026-41938

Vvveb

Descripción

Vvveb before version 1.0.8.2 contains an unrestricted file upload vulnerability in the media upload handler that allows authenticated users with media-upload permissions to bypass extension restrictions by uploading a .htaccess file to map .phtml extensions to the PHP handler. Attackers can upload a .phtml file containing arbitrary PHP code and trigger execution by sending an unauthenticated HTTP GET request to the uploaded file, resulting in remote code execution with web server privileges.

CVSS 8.8EPSS 0.541%Riesgo 0.92
Ver fuente
Publicación
2026-05-06 19:16:37
Versiones afectadas
<1.0.8.2
Tipo
Package
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H