Impact
Kunstmaan CMS allowed authenticated administrators to upload media files that bypassed the blacklist of disallowed extensions. Because the check for denied extensions was case‑sensitive and the stored filename was lower‑cased after upload, a mixed‑case executable extension such as "php" could be uploaded and stored in the web‑accessible media directory. The default blacklist also omitted several server‑executable types, so an uploaded executable could be executed directly by the web server. This flaw is a classic example of improper file type validation (CWE‑434), giving an attacker the ability to run arbitrary code on the host. The impact is full remote code execution on the system running the CMS.
Affected Systems
The vulnerability affects the Kunstmaan CMS ecosystem, including KunstmaanBundlesCMS, bundles‑cms, and media‑bundle components. Any installation of version 7.3.1 or earlier is vulnerable. The issue is resolved in version 7.3.2 and later releases.
Risk and Exploitability
The CVSS base score of 7.2 highlights a high‑severity risk. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers must first authenticate as a backend user with media upload privileges, which is typically granted to site administrators. Once authenticated, the attacker can upload malicious code and execute it via the web server, resulting in complete compromise of the affected system. The lack of publicly available exploit code does not reduce the risk, as the flaw is straightforward to script and deploy under the required authentication context.
OpenCVE Enrichment