An unauthenticated arbitrary file upload vulnerability exists in LibrettoCMS version 1.1.7 (and possibly earlier) contains an unauthenticated arbitrary file upload vulnerability in its File Manager plugin. The upload handler located at adm/ui/js/ckeditor/plugins/pgrfilemanager/php/upload.php fails to properly validate file extensions, allowing attackers to upload files with misleading extensions and subsequently rename them to executable .php scripts. This enables remote code execution on the server without authentication.
Metrics
Affected Vendors & Products
References
History
Tue, 05 Aug 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 05 Aug 2025 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Librettocms
Librettocms librettocms |
|
Vendors & Products |
Librettocms
Librettocms librettocms |
Mon, 04 Aug 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An unauthenticated arbitrary file upload vulnerability exists in LibrettoCMS version 1.1.7 (and possibly earlier) contains an unauthenticated arbitrary file upload vulnerability in its File Manager plugin. The upload handler located at adm/ui/js/ckeditor/plugins/pgrfilemanager/php/upload.php fails to properly validate file extensions, allowing attackers to upload files with misleading extensions and subsequently rename them to executable .php scripts. This enables remote code execution on the server without authentication. | |
Title | LibrettoCMS File Manager Arbitrary File Upload | |
Weaknesses | CWE-434 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-08-04T18:04:25.900Z
Updated: 2025-08-05T15:49:22.523Z
Reserved: 2025-08-01T15:35:32.468Z
Link: CVE-2013-10054

Updated: 2025-08-05T15:49:10.727Z

Status : Awaiting Analysis
Published: 2025-08-04T18:15:34.123
Modified: 2025-08-05T16:15:28.277
Link: CVE-2013-10054

No data.