Impact
ApiAdmin versions 5.0 and prior permit any logged‑in administrator to upload executable files to the web‑accessible directory public/upload/Ymd/ because the upload handler accepts the file extension verbatim and performs no validation or content checking. The uploaded file is then delivered by the web server, allowing an attacker to place a PHP file that can be executed directly over HTTP. This flaw relies on improper input handling and lack of file type restrictions, enabling an attacker with administrative login to run arbitrary code on the server, compromising confidentiality, integrity, and availability of the system.
Affected Systems
The vulnerability affects the ApiAdmin software, specifically all releases version 5.0 and earlier. No specific vendor or additional product variants are named, and version details beyond the upper bound are not provided.
Risk and Exploitability
The CVSS score is not supplied, and the EPSS metric is unavailable; the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the flaw presents a high‑risk remote code execution vector for any authenticated administrator who can upload a file. The lack of chunking or restrictions means exploitation can be performed locally by the admin or remotely if the vulnerability is exposed to an attacker capable of performing admin authentication, without additional conditions noted in the description.
OpenCVE Enrichment