Coppermine Gallery Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability exists in Coppermine Gallery version 1.6.25. This issue allows authenticated attackers to upload malicious PHP files via the plugin manager. Exploitation involves uploading a zipped PHP file containing system commands to the plugin directory, which can then be executed by accessing the uploaded plugin script.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the server where Coppermine Gallery is hosted.

Reproduction

To reproduce this vulnerability, log into an account with access to the plugin manager. Navigate to the plugin management page and upload a zip file containing a PHP script. The PHP script can include commands to be executed on the server. After uploading the zip file, access the PHP script through the web server to execute the embedded commands.

Added: Dec 15, 2025, 9:31 PM
Updated: Dec 15, 2025, 10:29 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
10.0
exploitability
6.8
remediation
0.0
relevance
1.4
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.