{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aunopimunopim/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:unopim:unopim:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-82524"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["UnoPim (\u003c 2.1.5)"],"_cs_severities":["high"],"_cs_tags":["web-application","rce","file-upload","cve-2026-82524"],"_cs_type":"advisory","_cs_vendors":["UnoPim"],"content_html":"\u003cp\u003eUnoPim versions before 2.1.5 are vulnerable to an authenticated arbitrary file upload flaw (CVE-2026-82524). The vulnerability resides in the TinyMCE image upload endpoint, which lacks sufficient validation of file extensions and MIME types. An attacker with administrative privileges can upload a PHP web shell to the application's public storage directory. Once uploaded, the attacker can trigger the malicious script by navigating to the file path returned in the server's HTTP response, resulting in remote code execution (RCE) on the underlying server. This vulnerability is significant because it allows a compromised administrative account to achieve full system control, bypassing intended restrictions on the file upload functionality.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker authenticates to the UnoPim administrative dashboard using valid or compromised credentials.\u003c/li\u003e\n\u003cli\u003eThe attacker navigates to the TinyMCE image upload feature within the application interface.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a request to the TinyMCE image upload endpoint containing a malicious PHP file payload.\u003c/li\u003e\n\u003cli\u003eThe UnoPim server receives the file and fails to perform server-side validation of the 'extension' or 'MIME type' attributes.\u003c/li\u003e\n\u003cli\u003eThe server stores the malicious PHP file within a public-facing directory on the web server storage disk.\u003c/li\u003e\n\u003cli\u003eThe application returns the URL path of the uploaded file to the attacker in an HTTP response.\u003c/li\u003e\n\u003cli\u003eThe attacker sends an HTTP GET request to the path of the uploaded PHP file.\u003c/li\u003e\n\u003cli\u003eThe web server executes the PHP code, enabling command execution or persistent backdoor access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full remote code execution on the server hosting the UnoPim instance. As the vulnerability requires administrative access, it is typically used for lateral movement or persistence after an initial account compromise. The impact includes potential full system compromise, data exfiltration from the database or storage, and the ability to pivot to other internal network resources.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade UnoPim to version 2.1.5 or later immediately to incorporate necessary file validation logic.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for HTTP POST requests to the TinyMCE image upload endpoint that contain unusual file extensions (e.g., .php, .phtml, .php7).\u003c/li\u003e\n\u003cli\u003eRestrict administrative access to the UnoPim dashboard to known-trusted management IP addresses.\u003c/li\u003e\n\u003cli\u003eAudit the public storage directory for unauthorized script files that do not match expected image file formats.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-02T21:16:04Z","date_published":"2026-09-02T21:16:04Z","id":"https://feed.craftedsignal.io/briefs/2026-09-unopim-rce/","summary":"UnoPim versions prior to 2.1.5 allow authenticated administrators to execute arbitrary code via an insecure TinyMCE image upload endpoint that fails to validate file extensions.","title":"Authenticated Arbitrary File Upload in UnoPim","url":"https://feed.craftedsignal.io/briefs/2026-09-unopim-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:unopim:unopim:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}