Impact
A flaw in the file upload feature of Zhao‑github ApiAdmin v5.0.1 permits an attacker to upload a crafted PHP file that the application executes. The vulnerability allows the attacker to run arbitrary PHP code on the hosting server, potentially giving full control over the system, including access to sensitive data and the ability to pivot to other internal resources. The impact is severe because it compromises both confidentiality and integrity of the affected environment.
Affected Systems
The vulnerability affects Zhao‑github ApiAdmin version 5.0.1. No other versions are known to be impacted, and there is no vendor-provided version range. Administrators must verify any installation of this product and version number.
Risk and Exploitability
The CVSS score is not provided, but the existence of remote code execution with an upload endpoint suggests a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through an unauthenticated or low‑privileged HTTP file‑upload endpoint that accepts PHP files. Exploitation would require remote access to the upload functionality and the ability to place a PHP file on the server.
OpenCVE Enrichment