CVE-2026-7733 Details
Description
A flaw has been found in funadmin up to 7.1.0-rc6. This affects the function UploadService::chunkUpload of the file app/common/service/UploadService.php of the component Frontend Chunked Upload Endpoint. This manipulation of the argument File causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: 59. To fix this issue, it is recommended to deploy a patch.
A vulnerability allowing unrestricted file uploads has been identified in Funadmin versions through 7.1.0-rc6. The issue arises in the UploadService component, specifically within the chunkUpload function of UploadService.php. The vulnerability is created by manipulating the file upload arguments, which bypasses security checks and allows the upload of executable files, such as PHP scripts. This flaw can be exploited remotely.
Users are advised to update to the patched version of Funadmin, which includes the necessary file validation in the chunkUpload method. The patch can be applied by merging the latest changes from the main branch.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 4, 2026CISA-ADP
Assessed May 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gitee.com/funadmin/funadmin/ | [email protected] | ProductVendor |
| https://gitee.com/funadmin/funadmin/issues/IJ8NXT | [email protected] | Issue TrackingVendor |
| https://gitee.com/funadmin/funadmin/pulls/59 | [email protected] | Source CodeVendor |
| https://vuldb.com/submit/807559 | [email protected] | Permission Required |
| https://vuldb.com/vuln/360908 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/360908/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| funadmin | <= 7.1.0-rc6 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 4, 2026 | New CVE Received | [email protected] |
Volerion