Impact
The vulnerability resides in Light0011 CMS’s ThinkPHP Upload class, allowing an attacker to upload arbitrary files under the control of a remote user. Because no validation or restriction is imposed on accepted file types or locations, a malicious actor can place executable code or web shells on the server, potentially leading to full server compromise. The weakness is specified as CWE-284 (Improper Access Control) and CWE-434 (Unrestricted Upload of File with Dangerous Type).
Affected Systems
Light0011 CMS, a rolling‑release project with an unmaintained issue tracker, has no pinned version numbers. The flaw affects every release of the CMS that includes the vulnerable Upload class until a patch is applied or the upload functionality is removed. The vendor has not yet responded to the reported issue and has not released a fix.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity vulnerability. EPSS is currently unavailable, so the probability of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Though the exploit has been released publicly, no confirmed exploitation has been reported. The attack can be carried out remotely by simply sending a crafted request to the upload endpoint, and the lack of payload restrictions makes exploitation straightforward for an attacker with network access to the CMS.
OpenCVE Enrichment