Executive brief
phpUploader is a web application used for managing file uploads. A security flaw allows anyone on the internet to view sensitive database information without logging in. This exposed data includes uploader IP addresses, security hashes, and internal file details, which could be used by attackers to compromise the privacy of users or plan further attacks.
Technical details
An unauthenticated information disclosure vulnerability exists in phpUploader versions prior to 2.0.2. The root cause is located in the index model, which performs an unbounded SQL SELECT query against the uploaded-files database table. The application then embeds the entire resulting dataset as a JSON-encoded object within an inline script block on the page. A remote, unauthenticated attacker can exploit this by simply requesting any application page, thereby gaining access to sensitive metadata including uploader IP addresses, Argon2ID password hashes, internal file paths, and SHA-256 file fingerprints. The issue was addressed in version 2.0.2 by limiting database queries to display-safe columns and improving JSON escaping.
Affected products
- shimosyan phpUploader before 2.0.2
Timeline
- 2026-06-29: patched: Version 2.0.2 released to address the vulnerability.
- 2026-06-29: advisory: CVE-2026-56124 published.