PT-2026-30688 · Brave Cms · Brave Cms
Para213
·
Published
2026-04-06
·
Updated
2026-04-06
·
CVE-2026-35164
CVSS v3.1
8.8
High
| AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Brave CMS versions prior to 2.0.6
Description
Brave CMS, an open-source CMS, contains an unrestricted file upload issue in the CKEditor upload functionality. The issue resides in the
ckupload method within the app/Http/Controllers/Dashboard/CkEditorController.php file. The method does not validate uploaded file types, relying solely on user input. This allows an authenticated user to upload executable PHP scripts, potentially leading to Remote Code Execution.Recommendations
Update to version 2.0.6
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Brave Cms