rootpwn

high · CVSS v3 7.2

CVE-2026-36467

Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticate…

Description

Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leading to remote server access by triggering a reverse shell.

Scores

Severity
high
CVSS v2
8.3
CVSS v3
7.2
CVSS v4
EPSS

← All CVEs