Impact
A deserialization flaw in the preview.php script of the WebUploader component used by yuan1994 tpadmin allows an attacker to submit crafted input that is processed without proper validation. The vulnerability can lead to execution of arbitrary code on the web server, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
All releases of yuan1994 tpadmin up through version 1.3.12 are affected. The component is identified by the CPE cpe:2.3:a:tpadmin_project:tpadmin and is no longer supported by the maintainer, so no official updates are expected for older versions.
Risk and Exploitability
The vulnerability has a CVSS score of 6.9, indicating moderate severity. EPSS is below 1%, suggesting a low overall exploitation probability at present. It is not listed in the CISA KEV catalog. Attack execution requires remote access, most likely via HTTP requests to the preview.php endpoint, and relies on the ability to send malicious serialized payloads.
OpenCVE Enrichment