Unrestricted File Upload Vulnerability in light0011 CMS by Light0011
CVE-2026-86305
Key Information:
Badges
What is CVE-2026-86305?
A significant vulnerability has been identified in the light0011 CMS, specifically within the Upload::upload function of the ThinkPHP library. This weakness permits unauthorized users to upload files without proper restrictions, potentially leading to unauthorized code execution. The flaw can be exploited remotely, increasing the risk as it could be used by an attacker to compromise the web application and potentially the underlying server. This issue was reported to the developers, but there has been no official response or patch available, leaving users vulnerable to potential attacks.
Affected Version(s)
cms c774dce31c6df0055568a8d5c53d964d99be199d
cms f72cf46f601efb2a0618c3814cc2f61380b38930
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
