Impact
The flaw resides in the file_put_contents call within the codeEditor.php file of the Save Handler component, allowing an attacker to supply arbitrary filenames and content. This results in unrestricted file upload capability, which can be used to place malicious scripts on the server and subsequently execute them. The weakness is classified under CWE-284 and CWE-434 and presents a remote code execution risk.
Affected Systems
JosephChuks php-file-manager-with-code-editor versions up to 3.0 are vulnerable. No patch information is currently available from the vendor, and the vulnerability applies to all installations of these versions.
Risk and Exploitability
The CVSS base score is 6.9, indicating a moderate impact. EPSS is not available, making it unclear how frequently this flaw is exploited in the wild. The vulnerability is not listed in CISA's KEV catalog. Because the attack vector is remote and the vendor has not released a fix, any system that accepts uploads may be affected if the component is deployed without additional mitigations.
OpenCVE Enrichment