Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Project Pier Arbitrary File Upload Vulnerability Allowing Remote Code Execution

Vulnerability

An unauthenticated arbitrary file upload vulnerability has been identified in Project Pier versions through 0.8.8. The issue resides in the file upload handler, which fails to properly validate file types or require authentication. This flaw enables remote attackers to upload malicious PHP files to a directory accessible via the web. Once uploaded, the files can be executed by accessing their URLs, leading to remote code execution.

Impact

Exploitation of this vulnerability allows for arbitrary file uploads, which can be leveraged to execute malicious PHP scripts on the server, resulting in remote code execution.

Reproduction

The vulnerability can be reproduced by uploading a PHP file through the application's file upload feature, which is accessible without authentication. The uploaded file is saved in a web-accessible directory with a predictable filename format, allowing for easy execution by requesting the file's URL. This vulnerability has been successfully exploited using a Metasploit module.

Added: Aug 8, 2025, 7:52 PM
Updated: Aug 8, 2025, 9:12 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
10.0
exploitability
9.8
remediation
0.0
relevance
0.3
threat
9.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.