Unrestricted File Upload Vulnerability in JosephChuks File Manager
CVE-2026-95500
6.9MEDIUM
What is CVE-2026-95500?
A vulnerability exists in the php-file-manager-with-code-editor where the file_put_contents function in codeEditor.php allows for arbitrary file uploads due to inadequate validation of the filename and content parameters. This flaw enables attackers to upload malicious files remotely, posing a significant risk to server integrity and data security. The vulnerability has been publicly disclosed, and efforts to inform the vendor about the exploit have not received a response.
Affected Version(s)
php-file-manager-with-code-editor 3.0
