Junglewise Threat Intelligence

CVE-2026-77681: CodeAstro Online Job Portal arbitrary file upload in update-profile.php

CVE-2026-77681 · Severity: medium · CVSS 6.3 · Published 2026-08-21

Vendors: CodeAstro.

Executive brief

CodeAstro Online Job Portal is a free PHP web application for job recruitment and management. The application fails to properly validate uploaded files in the profile update feature, allowing an attacker to upload malicious scripts (such as web shells) that can be executed on the server to achieve remote code execution and complete system compromise.

Technical details

The vulnerability is an arbitrary file upload flaw in the /users/update-profile.php endpoint, where the $_FILES['img']['name'] parameter is not properly validated for file type, extension, or content. An authenticated attacker can upload a PHP script disguised with an image filename to the /users/user-images/ directory, then access it via the web browser to execute arbitrary server-side code. The root cause is insufficient validation of uploaded file type and extension (no whitelist enforcement, no MIME type checking via exif_imagetype()). Successful exploitation requires user authentication and a valid account with an upd_id parameter, and results in unauthenticated remote code execution through the uploaded web shell. Patches should implement strict file extension whitelisting, server-side MIME type validation, random file renaming, and PHP execution restrictions on the upload directory.

Affected products

  • CodeAstro Online Job Portal 1.0

Timeline

  • 2026-07-06: disclosed: Vulnerability disclosed on GitHub
  • 2026-08-21: advisory: CVE-2026-77681 published to NVD

References