Back to overview

CVE-2026-10806

MEDIUM Exploitation: PoC
6.3
CVSS 3.1
Description
A vulnerability was found in mjperpinosa stumasy. The affected element is an unknown function of the file application/PHP/objects/updates/add_post.php. Performing a manipulation of the argument up_file_to_post results in unrestricted upload. The attack may be initiated remotely. The exploit has been made public and could be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.

Metadata

CVE ID
CVE-2026-10806
State
PUBLISHED
Assigner
VulDB
Reserved
2026-06-04 05:14 UTC
Published
2026-06-04 12:15 UTC
Last updated
2026-06-04 15:06 UTC
Primary CWE
CWE-434
Unrestricted Upload
Vendor / Product
mjperpinosa / stumasy
Sources
cve.org  ·  NVD

Severity & Metrics

6.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
mjperpinosa stumasy 25d695901fbb586bf184b8ba73456d8e5311656c, 79c86fce86a09adc6edcbd6d56115fbff14ed538, 327d1b0f2915ba79d7ef8ebb74553e987609d9be
Weakness (CWE)
CWESourceDescription
CWE-284 cna Improper Access Controls
CWE-434 cna Unrestricted Upload
CVSS scores (4)
ScoreSeverityVersionSourceVector
6.5 N/D 2.0 cna AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR
6.3 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
6.3 MEDIUM 3.0 cna CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
5.3 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
References (6)
Back to overview