Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Metanubix

#27659of 53,630
9.3Total CVSS
Vulnerabilities · 1
PT-2025-29142
9.3
2025-07-10
Unknown · Jquery File Upload · CVE-2025-34100
Name of the Vulnerable Software and Affected Versions: BuilderEngine version 3.5.0 Description: An unrestricted file upload issue exists due to the integration of elFinder 2.0 and the jQuery File Upload plugin. The plugin does not properly validate or restrict file types or locations during upload operations. This allows an attacker to upload a malicious .php file and execute arbitrary PHP code on the server under the context of the web server process. The vulnerability is exposed to unauthenticated users, resulting in full remote code execution. Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.