Junglewise Threat Intelligence

CVE-2026-82524: UnoPim arbitrary file upload in TinyMCE

CVE-2026-82524 · Severity: high · CVSS 7.2 · Published 2026-09-02

Vendors: Webkul.

Executive brief

UnoPim is an open-source product information management system used to manage and organize product catalogs. Authenticated administrators can upload arbitrary PHP files via the TinyMCE image editor due to missing file validation, then execute those files as web shells to run operating system commands and compromise the entire server.

Technical details

This is an unrestricted file upload vulnerability (CWE-434) in the TinyMCE image upload endpoint at POST /admin/tinymce/upload in the TinyMCEController. The vulnerable component in packages/Webkul/Admin/src/Http/Controllers/TinyMCEController.php fails to validate file extensions and MIME types; while the FileStorer helper includes sanitization for SVG files, other file types bypass validation entirely. An authenticated administrator can upload a PHP file to the public storage disk and immediately execute it by accessing the returned URL with arbitrary system commands. The vulnerability was fixed in version 2.1.5 by implementing an image allowlist, renaming uploaded files with cryptographically secure UUIDs, and adding the TinyMCEUploadRequest validation layer (commit 675dfb5).

Affected products

  • Webkul UnoPim before 2.1.5

Timeline

  • 2026-06-08: disclosed
  • 2026-06-10: patched: Fixed in version 2.1.5
  • 2026-09-02: advisory

References