Executive brief
ApiAdmin is a web administration interface used to manage APIs and backend services. This vulnerability allows an attacker to upload malicious PHP files to the server, leading to arbitrary code execution and potential complete compromise of the application and underlying systems.
Technical details
A file upload vulnerability in ApiAdmin v.5.0.1 fails to properly validate or restrict uploaded file types, allowing an attacker to upload crafted PHP files that are then executed by the web server. The vulnerability requires network access to the upload endpoint and likely does not require prior authentication, though preconditions depend on application configuration. Successful exploitation grants remote code execution with the privileges of the web server process, enabling full system compromise. Patch availability for this vulnerability is not documented in the provided advisory.
Affected products
- Zhao-github ApiAdmin 5.0.1
Timeline
- 2026-09-04: disclosed