PT-2026-53852 · Unknown · Redeight Cms
Jacek Czepil
·
Published
2026-06-30
·
Updated
2026-06-30
·
CVE-2026-53691
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
Redeight CMS version 1.0
Description
An unrestricted file upload flaw allows authenticated attackers to achieve Remote Code Execution. The issue occurs because the application does not validate file extensions or MIME types (the standard used to identify file formats). This allows the upload of arbitrary PHP scripts to the publicly accessible
/uploads/files/ directory, where they can be executed by the web server. The attack is performed via the POST /admin/index.php?module=pages&mode=FileAdd endpoint.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redeight Cms