Executive brief
php-file-manager-with-code-editor is a web-based file and code editor component. A flaw in the save handler allows remote attackers to upload arbitrary files through manipulation of filename and content parameters, potentially enabling malicious code execution or data compromise on the web server.
Technical details
The codeEditor.php component's Save Handler fails to properly validate the filename and content arguments passed to file_put_contents, allowing unrestricted file uploads. An unauthenticated remote attacker can exploit this over the network to upload arbitrary files to the server. The vulnerability enables arbitrary code execution if files can be uploaded to web-accessible locations.
Affected products
- JosephChuks php-file-manager-with-code-editor up to 3.0
Timeline
- 2026-09-22: disclosed: Vulnerability publicly disclosed; vendor did not respond to early notification
- 2026-09-22: other: Exploit details available in public domain