CVE-2026-36467 Details
Description
Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leading to remote server access by triggering a reverse shell.
A vulnerability in CuteNews version 2.1.2 has been identified, allowing remote authenticated users with access to the Media Manager panel to upload files with dangerous types. This unrestricted file upload can be exploited to execute arbitrary code within the web application's context, potentially leading to remote server access by triggering a reverse shell. The issue arises from inadequate file validation in the 'Upload by URL' feature of the media management module.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 21, 2026CISA-ADP
Assessed Sep 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/CuteNews/cutenews-2.0 | [email protected] | Vendor |
| https://github.com/CuteNews/cutenews-2.0/blob/master/core/modules/media.php | [email protected] | Source CodeVendor |
| https://github.com/UmbraDeorum/cutenews-2.0-CVEs-2026-Disclosure | [email protected] | BundleTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| CuteNews | 2.1.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 21, 2026 | New CVE Received | [email protected] |
| Sep 21, 2026 | CVE Modified | CISA-ADP |
Volerion