<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>W (&lt;= 3.18.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/w--3.18.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 04 Oct 2026 05:00:08 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/w--3.18.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution in W CMS via Path Traversal</title><link>https://feed.craftedsignal.io/briefs/2026-10-wcms-rce/</link><pubDate>Sun, 04 Oct 2026 05:00:08 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-wcms-rce/</guid><description>W CMS versions 3.18.0 and earlier are vulnerable to remote code execution and arbitrary file deletion due to insufficient path validation in the media management API.</description><content:encoded><![CDATA[<p>W CMS (vincent-peugnet/wcms) through version 3.18.0 contains a critical remote code execution vulnerability originating from improper input validation within the API endpoints responsible for media management. Authenticated editors can exploit the path handling logic in the /api/v0/media/upload/[<em>:path] endpoint to perform path traversal. By utilizing encoded dot-dot-slash (../) sequences, an attacker can bypass directory restrictions to write files, including malicious .php scripts, outside the intended media storage directory. Once placed, these scripts can be executed by the web server. Additionally, the /api/v0/media/[</em>:path] endpoint is vulnerable to arbitrary file deletion, allowing authenticated users to disrupt the application or remove security configuration files. This vulnerability represents a significant risk to the integrity and availability of the host server environment.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker authenticates as an editor user within the target W CMS instance.</li>
<li>Attacker crafts a malicious HTTP POST request to /api/v0/media/upload/[*:path].</li>
<li>The request includes an encoded directory traversal sequence (e.g., %2e%2e%2f) within the path parameter.</li>
<li>The application fails to sanitize the path, allowing the attacker to target sensitive web-accessible directories.</li>
<li>The attacker uploads a web shell disguised as a .php file to an executable location.</li>
<li>The attacker navigates to the location of the uploaded file via the browser to trigger code execution.</li>
<li>Optional: The attacker uses the DELETE method on /api/v0/media/[*:path] to remove application logs or critical files for post-exploitation cleanup.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation grants an authenticated editor full remote code execution capabilities on the underlying host server. This allows for total system compromise, including the ability to exfiltrate data, modify web content, or pivot into the internal network. Attackers may also cause denial-of-service conditions by deleting arbitrary application files necessary for CMS functionality.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for detection engineering teams:</p>
<ul>
<li>Upgrade W CMS to a version beyond 3.18.0 immediately to remediate CVE-2026-105123.</li>
<li>Deploy the Sigma rules provided in this brief to detect anomalous API requests targeting the media management endpoints.</li>
<li>Implement access control reviews for accounts with &quot;editor&quot; permissions, as these are the primary vector for this vulnerability.</li>
<li>Monitor web server access logs for anomalous POST and DELETE requests to /api/v0/media/ paths containing path traversal characters like &quot;../&quot; or URL-encoded equivalents.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>rce</category><category>vulnerability</category><category>path-traversal</category></item></channel></rss>