Unrestricted Upload Vulnerability in Mwasikz Robo-Cafe-RMS Software
CVE-2026-102263

5.1MEDIUM

Key Information:

Vendor

Mwasikz

Vendor
CVE Published:
29 September 2026

What is CVE-2026-102263?

A vulnerability exists in the Mwasikz Robo-Cafe-RMS software that allows attackers to exploit an unknown function located in manage-food.php, enabling unrestricted file upload. This flaw can be exploited remotely, facilitating potential unauthorized access to the affected system. The vendor was notified of this issue but has not responded. As the product uses a rolling release model, specific versioning details for updates are unavailable. Users are advised to implement necessary security measures to mitigate the risk. More information can be found at the referenced sources.

Affected Version(s)

robo-cafe-rms 228c44a02823f04e85db32b7137809a2856148fc

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dexter-morgan (VulDB User)
VulDB CNA Team
.