HIGHVulnerability

CVE-2026-82524

UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP files through the TinyMCE image upload endpoint due to missing file extension and MIME type validation. Attackers can upload a PHP web shell to the public storage disk and execute arbitrary operating system commands on the server by accessing the uploaded file at the URL returned in the server response.

Properties

severity
HIGH
score
7.2
cve_id
CVE-2026-82524
signal_observed_at
2026-09-23T22:44:45+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
published_at
2026-09-02T20:17:39.210
last_modified
2026-09-23T17:17:45.610

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Unrestricted Upload of File with Dangerous Type

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82524 — Ninja Signal Threat Intelligence | Ninja Signal