PT-2026-25971 · Danvei233 · Xiaoheifs
Published
2026-03-18
·
Updated
2026-03-18
·
CVE-2026-28674
CVSS v3.1
7.2
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and including 0.3.15, the
AdminPaymentPluginUpload endpoint lets admins upload any file to plugins/payment/. It only checks a hardcoded password (qweasd123456) and ignores file content. A background watcher (StartWatcher) then scans this folder every 5 seconds. If it finds a new executable, it runs it immediately, resulting in RCE. Version 4.0.0 fixes the issue.Fix
Using Hardcoded Credentials
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xiaoheifs