Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Kordil EDMS Unauthenticated Arbitrary File Upload Vulnerability Allowing Remote Code Execution

Vulnerability

A vulnerability allowing unauthenticated arbitrary file uploads has been identified in Kordil EDMS version 2.2.60rc3. The application includes an upload endpoint in 'users_add.php' that permits attackers to upload files to the '/userpictures/' directory without authentication. This vulnerability can be exploited to execute remote code by uploading a PHP payload and accessing it through a direct HTTP request.

Impact

Exploitation of this vulnerability allows for arbitrary file uploads, which can be used to upload malicious files that are executed on the server, leading to remote code execution.

Reproduction

To reproduce this vulnerability, send a POST request to 'users_add.php' with the 'upload_fd31' parameter containing a PHP file payload. Include the 'add_fd0' and 'add_fd27' parameters with the same filename. After the file is uploaded, it can be accessed via 'userpictures/[filename].php' to execute the payload.

Added: Aug 5, 2025, 8:42 PM
Updated: Aug 5, 2025, 10:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
10.0
exploitability
9.8
remediation
0.0
relevance
0.3
threat
9.5
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.