Unknown · Jquery File Upload · CVE-2025-34100
Name of the Vulnerable Software and Affected Versions:
BuilderEngine version 3.5.0
Description:
An unrestricted file upload issue exists due to the integration of elFinder 2.0 and the jQuery File Upload plugin. The plugin does not properly validate or restrict file types or locations during upload operations. This allows an attacker to upload a malicious .php file and execute arbitrary PHP code on the server under the context of the web server process. The vulnerability is exposed to unauthenticated users, resulting in full remote code execution.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.