{"id":"CVE-2026-88419","published":"2026-09-22T20:17:11.083","lastModified":"2026-09-24T21:25:27.050","description":"An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=thumbUpload) of WuzhiCMS 5.0.0 allows an authenticated low-privileged member to upload a crafted .php file and execute arbitrary PHP code on the server, because the stored file extension is taken verbatim from the client-supplied filename with no extension allowlist or content validation and the file is written to the web-accessible uploadfile/ directory, from which the web server executes PHP.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-434"],"vendors":[],"products":[],"references":[{"url":"https://github.com/15536818056/CVE/issues/6","tags":[]},{"url":"https://github.com/15536818056/CVE/issues/6","tags":[]}],"exploitRefs":[{"url":"https://github.com/15536818056/CVE/issues/6","tags":[]},{"url":"https://github.com/15536818056/CVE/issues/6","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows an authenticated low-privileged user to upload a .php file, leading to arbitrary code execution on the server due to lack of proper file extension validation and content checks.","exploitability":"Exploitation is relatively straightforward given the lack of validation, and requires an authenticated user with low privileges.","blast_radius":"If exploited, the impact is high as it can lead to full server compromise and arbitrary code execution.","remediation":"Upgrade to WuzhiCMS 5.0.1 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","auth-bypass","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:55:33.499Z"}}