-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| elefant/cms | composer | < 1.3.13 | 1.3.13 |
The vulnerability explicitly affects the /filemanager/upload/drop endpoint's file upload functionality. The PoC demonstrates uploading a .php5 file containing PHP code, which was improperly allowed. While exact function names aren't provided in disclosures, the endpoint's handler function is clearly responsible for insufficient file type validation. The CWE-434 classification and attack pattern confirm this is an unrestricted dangerous file type upload issue.
Ongoing coverage of React2Shell