Unrestricted Upload Vulnerability in Funadmin Frontend Chunked Upload Component
CVE-2026-7733
Key Information:
Badges
What is CVE-2026-7733?
A vulnerability has been identified in Funadmin versions up to 7.1.0-rc6 within the Frontend Chunked Upload Endpoint. It stems from a flaw in the UploadService::chunkUpload function located in app/common/service/UploadService.php. This weakness allows an attacker to manipulate the File argument, resulting in unrestricted file uploads. Such exploitation can be executed remotely without authentication, increasing the risk for users. It is recommended to apply patch 59 to mitigate this security issue.
Affected Version(s)
funadmin 7.1.0-rc1
funadmin 7.1.0-rc2
funadmin 7.1.0-rc3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
