Impact
The vulnerability in WuzhiCMS 5.0.0 allows an authenticated low‑privileged member to upload a crafted PHP file to the thumbnail‑upload endpoint and execute arbitrary PHP code on the server. Because the application accepts the file extension directly from the client and writes the file to a web‑accessible directory with no validation, an attacker can run malicious scripts with the permissions of the web server.
Affected Systems
This flaw affects the WuzhiCMS content management system, specifically version 5.0.0. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity for this vulnerability. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote code execution via a thumbnail‑upload endpoint that accepts any file type and stores the uploaded file in a web‑accessible directory, allowing an authenticated low‑privileged member to upload and execute a malicious PHP script. This direct execution capability grants the attacker full control over the web server, making the risk significant.
OpenCVE Enrichment