PT-2026-53852 · Unknown · Redeight Cms

Jacek Czepil

·

Published

2026-06-30

·

Updated

2026-06-30

·

CVE-2026-53691

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
Name of the Vulnerable Software and Affected Versions Redeight CMS version 1.0
Description An unrestricted file upload flaw allows authenticated attackers to achieve Remote Code Execution. The issue occurs because the application does not validate file extensions or MIME types (the standard used to identify file formats). This allows the upload of arbitrary PHP scripts to the publicly accessible /uploads/files/ directory, where they can be executed by the web server. The attack is performed via the POST /admin/index.php?module=pages&mode=FileAdd endpoint.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53691

Affected Products

Redeight Cms