Executive brief
FeehiCMS is a content management system that includes a UEditor widget for file uploads. Due to improper authentication controls and disabled CSRF protection, unauthenticated attackers can upload arbitrary files (including executable scripts and configuration files) to the server, potentially leading to remote code execution or data exposure.
Technical details
The vulnerability exists in the UeditorAction::init function within the UEditor Widget component. The backend's AccessControl configuration whitelists the entire 'assets/*' action namespace without authentication, exposing multiple file upload endpoints (uploadImage, uploadFile supporting 30+ extensions including .txt, .md, .xml, .zip) and file enumeration actions to unauthenticated attackers. CSRF protection is explicitly disabled in UeditorAction::init, eliminating a secondary defense. An unauthenticated remote attacker can directly upload arbitrary files or enumerate existing files without any authentication requirement or valid session token.
Affected products
- liufee FeehiCMS up to 2.1.1
Timeline
- 2026-07-22: disclosed: Issue reported on GitHub
- 2026-09-07: advisory: Published in NVD
- 2026-09-07: other: Public exploit available