Code-Projects Simple Forum Unrestricted File Upload Vulnerability

Vulnerability

A critical arbitrary file upload vulnerability has been identified in Code-Projects Simple Forum version 1.0. The issue resides in the '/forum1.php' file, where the application fails to properly validate uploaded files. This lack of validation allows unauthenticated users to upload malicious PHP scripts disguised as images. Once uploaded, these scripts can be executed via a web browser, potentially leading to a complete server compromise.

Impact

Exploitation of this vulnerability allows for arbitrary PHP code execution on the server, with the potential for remote code execution, full system compromise, data leakage, unauthorized data modification, and disruption of service.

Reproduction

To reproduce this vulnerability, authenticate to the application to obtain a valid PHP session ID. Then, send a POST request to '/forum1.php' with the 'file' parameter containing a PHP script payload, disguised as an image. After uploading, the malicious file can be accessed and executed from the web root directory.

Added: Jun 29, 2025, 6:20 AM
Updated: Jun 29, 2025, 6:20 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.6
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.