Executive brief
Pheditor, a web-based PHP file editor, contains a flaw in its initial setup process that allows anyone to bypass security and take control of the application. If the default password has not been changed, an attacker can reset the administrator password to a value of their choice without knowing the original one. This grants the attacker full access to edit or create files on the server, potentially leading to a complete system takeover.
Technical details
An authentication bypass exists in `pheditor.php` due to insufficient validation during the forced password-change flow. When the application detects the default password ('admin') is still set, it enters a branch that checks if the stored password is the default, but fails to verify that the user-provided 'current password' matches that default. An attacker can provide any non-empty value for the current password along with a new password to successfully reconfigure the administrative credentials. This vulnerability allows a remote, unauthenticated attacker to gain full administrative access to the file editor. The issue is fixed in version 2.0.8.
Affected products
- pheditor pheditor < 2.0.8
Timeline
- 2026-07-23: disclosed
- 2026-07-23: patched: Fixed in version 2.0.8
- 2026-07-24: advisory