Executive brief
SueamCMS, a content management system, contains a critical security flaw in its file management component. An attacker can upload malicious files to the server without any authorization or security checks. This allows a remote actor to take full control of the website, potentially leading to data theft, site defacement, or a complete service shutdown.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in SueamCMS v.0.1.2 within the 'mgt_file.php' component. The application fails to validate or filter uploaded file extensions and content, and it appears to rely on insecure cookie-based checks that do not prevent unauthorized access. A remote, unauthenticated attacker can exploit this by sending a specially crafted POST request containing a malicious PHP script. Once uploaded, the attacker can access the file directly via the web server to achieve remote code execution (RCE) with the privileges of the web service user.
Affected products
- SueamCMS Project SueamCMS 0.1.2
Timeline
- 2025-09-12: advisory: NVD publication date