Junglewise Threat Intelligence

CVE-2018-25412: Delta Sql arbitrary file upload in docs_upload.php

CVE-2018-25412 · Severity: critical · CVSS 9.8 · Published 2026-05-30

Executive brief

Delta Sql is an open-source tool used by developers to manage and synchronize database schema changes. A security flaw in the software allows unauthorized individuals to upload files to the server without a password. An attacker could use this to upload and run malicious code, potentially leading to a complete takeover of the server and access to the managed databases.

Technical details

An arbitrary file upload vulnerability exists in Delta Sql 1.8.2 due to missing authentication and insufficient file validation in the 'docs_upload.php' component. An unauthenticated remote attacker can exploit this by sending a specially crafted POST request containing multipart form data to the vulnerable endpoint. Because the application does not restrict the type of files being uploaded, an attacker can upload a PHP script to the web-accessible upload directory. Once uploaded, the attacker can execute the script by navigating to its URL, resulting in remote code execution (RCE) with the privileges of the web server user.

Affected products

  • Delta Sql Team Delta Sql 1.8.2

Timeline

  • 2018-10-25: disclosed: Initial exploit published on Exploit-DB
  • 2026-05-30: advisory: CVE published and NVD record created

References