Impact
Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload flaw that permits an attacker to upload arbitrary files. The lack of file type and content validation allows the uploaded data to be treated as executable, giving the attacker the ability to run code on the host. This weakness corresponds to CWE‑434, an unrestricted upload of a dangerous file type.
Affected Systems
The observed vulnerability exists in Falco Solutions PHPPageBuilder version 0.31.0. No additional affected versions have been identified.
Risk and Exploitability
The EPSS score is not provided, yet the vulnerability’s nature—unrestricted file upload leading to remote code execution—implies a high likelihood of exploitation if left unmitigated. The file upload endpoint is publicly accessible, so the attack vector is the web interface. Although the vulnerability is not listed in CISA’s KEV catalog, its potential impact is severe. Until a vendor patch is available, the risk remains elevated and attackers could deploy web shells or other malicious payloads immediately.
OpenCVE Enrichment