Impact
Authenticated editors can exploit the POST /api/v0/media/upload/[path] endpoint by supplying an unvalidated file path. The API accepts .php files without sanitizing path components, allowing an attacker to place arbitrary files in any directory, including the web root. Executing a .php file grants remote code execution, while the DELETE /api/v0/media/[path] endpoint permits deletion of arbitrary files. The flaw exemplifies CWE‑434: Unvalidated File Upload.
Affected Systems
The vulnerable product is vincent‑peugnet’s W CMS (wcms) version 3.18.0 and earlier. No other vendors or product lines are reported to be affected. Operators of self‑hosted wcms instances should confirm their installation version against the 3.18.0 baseline before applying any remediation.
Risk and Exploitability
The CVSS score of 8.7 indicates a high‑severity issue requiring authenticated access. The EPSS score is not available, but the lack of a public exploit and the requirement for editor credentials mean exploitation is possible only in environments where an attacker can gain or mimic such privileges. Although not listed in the CISA KEV catalog, the potential for remote code execution makes this a high‑priority risk for exposed wcms installations.
OpenCVE Enrichment