CVE-2026-82524

UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP files through the TinyMCE image upload endpoint due to missing file extension and MIME type validation. Attackers can upload a PHP web shell to the public storage disk and execute arbitrary operating system commands on the server by accessing the uploaded file at the URL returned in the server response.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 20:17

Updated : 2026-09-03 13:06


NVD link : CVE-2026-82524

Mitre link : CVE-2026-82524

CVE.ORG link : CVE-2026-82524


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type