Impact
This vulnerability involves an authenticated administrator being able to upload arbitrary files through the TinyMCE image upload endpoint because the application does not validate the file extension or MIME type. An attacker can upload a PHP web shell to the public storage disk, then execute arbitrary operating system commands on the server by accessing the uploaded file at the URL returned in the response. The result is complete remote code execution on the server.
Affected Systems
The affected product is unopim, version 2.1.4 and earlier. The upgrade to version 2.1.5 or later includes the fix for the missing validation logic in the TinyMCE image upload endpoint.
Risk and Exploitability
With a CVSS score of 8.6, this flaw is considered high severity. The attack requires the attacker to possess authenticated administrator privileges, but the impact is catastrophic once accessed: arbitrary code execution on the web server. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the combination of authentication requirement and high impact makes the risk significant for any environment running the affected versions.
OpenCVE Enrichment