Path Traversal Vulnerability in danpros HTMLy Affected by Delete Username Endpoint
CVE-2026-18644
Key Information:
Badges
What is CVE-2026-18644?
A path traversal vulnerability has been identified in danpros HTMLy, specifically within the Delete Username Endpoint functionality of the file /system/htmly.php. Remote attackers can exploit this weakness by manipulating the argument 'File' to access unauthorized files on the system. The exploit method is publicly known, raising significant security concerns. Communication attempts with the vendor regarding this issue have gone unanswered, leaving users at risk of potential attacks.
Affected Version(s)
HTMLy 3.1.0
HTMLy 3.1.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
