{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-95499/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:josephchuks:php-file-manager-with-code-editor:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-95499"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["php-file-manager-with-code-editor (\u003c= 3.0)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","remote-code-execution","file-upload","cve-2026-95499"],"_cs_type":"advisory","_cs_vendors":["JosephChuks"],"content_html":"\u003cp\u003eCVE-2026-95499 identifies a critical security flaw in the 'php-file-manager-with-code-editor' application, specifically affecting versions up to 3.0. The vulnerability stems from insecure handling of user-supplied data in the 'files' argument passed to the 'move_uploaded_file' function within 'filemanager.php'. This flaw permits remote, unauthenticated attackers to bypass intended restrictions and upload arbitrary files - potentially including malicious PHP scripts - directly to the web server's filesystem. Given the application's nature as a file manager and code editor, successful exploitation leads to remote code execution (RCE) as the web service user. The vendor was notified of the disclosure but remained unresponsive, leaving the vulnerability unpatched in the latest version. Organizations hosting this software are at significant risk of complete server compromise if exposed to the internet.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the execution of arbitrary code on the underlying host, facilitating data exfiltration, lateral movement, or complete system takeover. As the affected software is intended for managing files and editing code, attackers can easily maintain persistence or leverage existing server functionality to extend their access. There are no known patches, making decommissioning or strict network isolation the primary defensive measures.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately isolate the host running php-file-manager-with-code-editor from the internet.\u003c/li\u003e\n\u003cli\u003eIf the service is required, implement stringent web application firewall (WAF) rules to inspect and block POST requests to 'filemanager.php' that contain suspicious file extensions (e.g., .php, .phtml, .php7) within the 'files' parameter.\u003c/li\u003e\n\u003cli\u003eAudit the server filesystem for unexpected files in directories managed by the application, focusing on web-accessible paths.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous POST requests directed at 'filemanager.php' that do not originate from expected administrative IP addresses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T14:36:45Z","date_published":"2026-09-22T14:36:45Z","id":"https://feed.craftedsignal.io/briefs/2026-09-php-file-manager-rce/","summary":"A vulnerability (CVE-2026-95499) in php-file-manager-with-code-editor versions 3.0 and earlier allows remote attackers to perform unrestricted file uploads by manipulating the 'files' argument.","title":"Unrestricted File Upload Vulnerability in php-file-manager-with-code-editor","url":"https://feed.craftedsignal.io/briefs/2026-09-php-file-manager-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-95499","version":"https://jsonfeed.org/version/1.1"}