Impact
An unrestricted file upload in CuteNews 2.1.2’s Media Manager panel allows authenticated users to upload files of any type. An attacker can upload a malicious script that the application executes, enabling arbitrary code execution and triggering a reverse shell. This leads to full remote server access in the web application context. The weakness corresponds to CWE-434: Unrestricted Upload of File with Dangerous Type.
Affected Systems
The vulnerability is present in CuteNews version 2.1.2, specifically in the file core/modules/media.php. No other versions are currently documented as affected.
Risk and Exploitability
Based on the description, it is inferred that the attack vector involves an authenticated user with access to the Media Manager panel uploading a malicious file. The CVSS score is 7.2, and no EPSS data is available. Exploitation requires only authentication and access to the Media Manager. The possibility of arbitrary code execution makes the risk high for any site using CuteNews 2.1.2. Since the vulnerability is not listed in the CISA KEV catalog, it is not known to have active exploitation but could be a high‑value target for attackers with legitimate user credentials.
OpenCVE Enrichment