Impact
Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload flaw that permits an attacker to upload arbitrary files. The lack of file type and content validation allows the uploaded data to be treated as executable, giving the attacker the ability to run code on the host. This weakness corresponds to CWE‑434, an unrestricted upload of a dangerous file type.
Affected Systems
The observed vulnerability exists in Falco Solutions PHPPageBuilder version 0.31.0. No additional affected versions have been identified.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low but non-zero probability of exploitation. The CVSS score of 7.3 reflects a high severity level for this unrestricted file upload vulnerability. The publicly accessible upload endpoint presents a web‑interface attack vector, enabling attackers to upload arbitrary files that can be executed, leading to remote code execution. Although the vulnerability is not listed in CISA’s KEV catalog, its potential impact remains severe. Until a vendor patch is available, the risk is elevated and attackers could deploy web shells or other malicious payloads.
OpenCVE Enrichment