Unrestricted File Upload Vulnerability in GreenCMS by GreenCMS
CVE-2026-7044
Key Information:
Badges
What is CVE-2026-7044?
A vulnerability exists in versions of GreenCMS up to 2.3 that allows attackers to exploit the 'themeadd' function via the /index.php?m=admin&c=custom&a=themeadd endpoint. This flaw permits unrestricted file uploads, enabling remote attackers to upload malicious files without proper authorization. The issue primarily affects unsupported products, increasing the risk of exploitation. It's crucial for users of affected versions to be aware of this vulnerability and take necessary precautions to secure their systems.
Affected Version(s)
GreenCMS 2.0
GreenCMS 2.1
GreenCMS 2.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
