Executive brief
BurgerEditor is a content management plugin for baserCMS used to manage website content and files. The vulnerability allows authenticated users to upload files with dangerous extensions (such as PHP) to public directories, enabling arbitrary PHP code execution on the web server. This could lead to complete website compromise, data theft, or use of the server for further attacks.
Technical details
BurgerEditor versions 3.2.0–3.4.0 and 2.28.0–2.30.0 contain insufficient validation of uploaded files (CWE-434). When the Bge.allowedAdmin setting is enabled, the plugin permits executable file extensions to be saved to public directories without proper restrictions. An authenticated attacker can exploit this to upload arbitrary PHP files to a web-accessible location (files/bgeditor/img/ or files/bgeditor/other/). The vulnerability requires login access but allows unauthenticated access to the uploaded PHP file via direct URL, leading to remote code execution. The vendor patched this in BurgerEditor v3.4.1 and v2.30.1 by implementing server-side extension blacklisting and adding .htaccess rules to prevent execution in upload directories.
Affected products
- D-ZERO CO.,LTD. BurgerEditor 3.2.0 through 3.4.0; 2.28.0 through 2.30.0
Timeline
- 2026-09-10: disclosed: CVE-2026-84063 published
- 2026-09-04: patched: Fixes released in BurgerEditor v3.4.1 and v2.30.1