Navigate CMS Cross-Site Request Forgery Vulnerability Allowing Arbitrary File Uploads

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in Navigate CMS version 2.8.7. This vulnerability allows attackers to upload malicious extensions by exploiting the extension upload feature, which lacks proper validation. The issue arises when an authenticated administrator is tricked into interacting with a crafted HTML page that initiates the file upload.

Impact

Exploitation of this vulnerability could lead to unauthorized file uploads, potentially allowing for the execution of malicious code or the introduction of harmful files into the application.

Reproduction

To reproduce this vulnerability, an authenticated administrator must be persuaded to open a specially crafted HTML page. This page should include a script that uploads a malicious ZIP file containing a PHP payload disguised as an image. Once the file is uploaded, the PHP script can be executed by accessing it directly on the server.

Added: Jan 30, 2026, 11:20 PM
Updated: Jan 30, 2026, 11:20 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
7.7
remediation
7.7
relevance
2.5
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.