CVE-2026-82524 UnoPim before 2.1.5 contains an authenticated file… — CVE Notify — TG.ME

🚨 CVE-2026-82524
UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP files through the TinyMCE image upload endpoint due to missing file extension and MIME type validation. Attackers can upload a PHP web shell to the public storage disk and execute arbitrary operating system commands on the server by accessing the uploaded file at the URL returned in the server response.

🎖@cveNotify
Ashutosh Jena · maverick-vf142
Remote Code Execution (RCE) via Unrestricted File Upload in UnoPim v2.1.4
Executive Summary During a security assessment of UnoPim v2.1.4, I identified a critical Remote Code Execution (RCE) vulnerability. The flaw stems from an unrestricted file upload mechanism within th
September 2, 2026 3 1