Remote Code Execution Vulnerability in Neethuharii CafeManagement Plugin
CVE-2026-96513
What is CVE-2026-96513?
A significant security vulnerability has been identified in the Neethuharii CafeManagement application, specifically within the AddProductCode.php file. This flaw allows an attacker to perform an unrestricted file upload by manipulating the image argument, potentially leading to remote code execution. The vulnerability can be exploited remotely, making it crucial for users to take immediate action to mitigate the risk. Despite the vendor being informed of this issue, no response has been received, and the details regarding affected product updates have not been disclosed due to the rolling release system employed by the vendor.
Affected Version(s)
CafeManagement 5f743043a9a04f903678697f061d2e220e544c09
CafeManagement 66c837020e25af4866cb69b23ec3af4e0e1510c9
CafeManagement f80fe4442d5e15af5c78df3f22177a131c1e6f32
