{"id":"CVE-2026-36467","published":"2026-09-21T16:17:07.470","lastModified":"2026-09-21T16:17:07.470","description":"Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leading to remote server access by triggering a reverse shell.","cvssScore":7.2,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-434"],"vendors":[],"products":[],"references":[{"url":"https://github.com/CuteNews/cutenews-2.0","tags":[]},{"url":"https://github.com/CuteNews/cutenews-2.0/blob/master/core/modules/media.php","tags":[]},{"url":"https://github.com/UmbraDeorum/cutenews-2.0-CVEs-2026-Disclosure","tags":[]}],"exploitRefs":[{"url":"https://github.com/CuteNews/cutenews-2.0","tags":[]},{"url":"https://github.com/CuteNews/cutenews-2.0/blob/master/core/modules/media.php","tags":[]},{"url":"https://github.com/UmbraDeorum/cutenews-2.0-CVEs-2026-Disclosure","tags":[]}],"hasPoc":true,"ai":{"summary":"This vulnerability allows remote authenticated users to execute arbitrary code by uploading a file with a dangerous type, leading to potential remote server access.","exploitability":"Exploitation requires access to the Media Manager panel and is moderately difficult due to authentication requirements but straightforward once gained.","blast_radius":"If exploited, this can result in full control over the affected web application’s server environment, impacting all users and data.","remediation":"Update to a patched version of CuteNews or apply a security patch if available.","tags":["rce","web","auth-bypass","code-execution"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:17:02.491Z"}}