Description
A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. The manipulation of the argument File results in unrestricted upload. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted File Upload
Action: Apply Patch
AI Analysis

Impact

The setAvatar function accepts a File argument that can be manipulated to upload any file type without validation of content or type. The vendor does not perform checks on the file being uploaded. The uploaded files are saved in a directory that is directly accessible from the web. Because of this, a malicious user could upload a non‑image file, for example a PHP script, into that directory. It is inferred that if the web server is configured to execute scripts in that directory, the uploaded script could be run, which would provide remote code execution, although the official description does not explicitly state that this outcome is guaranteed.

Affected Systems

All installations of WuzhiCMS up to and including version 4.1.0 are affected. The flaw resides in the member::setAvatar method of the avatar upload component accessed via /index.php?m=member&f=user&v=setAvatar.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity level. The EPSS score is below 1%, suggesting that exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote and does not require authentication; an attacker can reach the upload endpoint from any network‑connected device and submit a crafted file. Because the upload allows arbitrary files to be stored in a web‑accessible directory, it is inferred that execution of a malicious script may be possible depending on server configuration, potentially leading to remote code execution. However this is an inference based on the upload path, not a confirmed feature in the description.

Generated by OpenCVE AI on September 20, 2026 at 15:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest WuzhiCMS patch if an updated version is available.
  • If a patch is not available, relocate the upload directory outside the web root or configure the web server to deny script execution in that directory.
  • Add server‑side validation to allow only approved image file types and reject executables or other non‑image uploads.

Generated by OpenCVE AI on September 20, 2026 at 15:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. The manipulation of the argument File results in unrestricted upload. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Title WuzhiCMS Avatar Upload index.php setAvatar unrestricted upload
First Time appeared Wuzhicms
Wuzhicms wuzhicms
Weaknesses CWE-284
CWE-434
CPEs cpe:2.3:a:wuzhicms:wuzhicms:*:*:*:*:*:*:*:*
Vendors & Products Wuzhicms
Wuzhicms wuzhicms
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Wuzhicms Wuzhicms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-17T15:30:00.655Z

Reserved: 2026-09-15T08:44:39.948Z

Link: CVE-2026-91849

cve-icon Vulnrichment

Updated: 2026-09-17T15:29:56.700Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:43.003

Modified: 2026-09-17T16:18:29.010

Link: CVE-2026-91849

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:00:14Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-434

    Unrestricted Upload of File with Dangerous Type