Executive brief
Diem is an open-source content management framework built on Symfony. A vulnerability in the widget editor component allows authenticated users with widget-editing privileges to upload arbitrary files, including PHP scripts, to a web-accessible directory. If the web server is configured to execute PHP files, this enables remote code execution under the web server's account.
Technical details
The vulnerability is an unrestricted file upload flaw in the widget media form component (dmFrontPlugin/lib/dmWidget/media/dmWidgetContentBaseMediaForm.php). The vulnerable code uses sfValidatorFile without enforcing a file-type allowlist and uploads files to /uploads/widget/ with their original extensions intact. An authenticated attacker with widget_edit privileges can craft a multipart form submission to POST /index.php/+/dmWidget/edit to upload a PHP file. The file is stored in a web-accessible directory and executed by the PHP interpreter, resulting in remote code execution. The root cause is the absence of file-type validation, content inspection, or a non-executable storage policy. No patch has been released by the project maintainers.
Affected products
- diem-project Diem up to 5.1.3
Timeline
- 2026-07-17: disclosed: Issue reported on GitHub
- 2026-08-31: advisory: CVE published