-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| phpmyfaq/phpmyfaq | composer | = 3.2.5 | 3.2.6 |
The vulnerability stems from two key mechanisms: 1) File storage logic that uses MD5 hashes for filenames/paths without preserving extensions, allowing bypass of .html checks. 2) Content-Type handling that defaults to HTML when no extension exists. The first function enables payload storage and predictable access, while the second enables dangerous content execution. These components are fundamental to the described attack flow of uploading extensionless .html files and having them rendered as active content.
Ongoing coverage of React2Shell