Impact
BurgerEditor versions 3.2.0 to 3.4.0 include an unrestricted upload feature that accepts files of dangerous types. An authenticated attacker who can log into the application can submit a file containing malicious PHP code, which the server may store and later execute. This flaw provides the attacker with the ability to run arbitrary PHP code on the host, compromising confidentiality, integrity, and availability of the system.
Affected Systems
D-ZERO CO., LTD. BurgerEditor 3.2.0 through 3.4.0 are vulnerable. No later sub‑versions are affected according to the current data. The vulnerability applies to all installations that expose the file upload functionality to logged‑in users.
Risk and Exploitability
With a CVSS score of 8.5, the vulnerability is classified as high impact. The EPSS score is not available, and it is not listed in CISA KEV, indicating no known exploits are tracked. Exploitation requires authentication to BurgerEditor, meaning only users with valid credentials can trigger the upload. Once the file lands in a web‑executable directory, the attacker can run PHP code with the privileges of the web server.
OpenCVE Enrichment