Kiamo PHP Code Execution Vulnerability

Vulnerability

A vulnerability allowing authenticated administrative users to execute arbitrary PHP code on the server has been identified in Kiamo versions prior to 8.4. This issue arises from an administrative feature that exposes a script execution capability.

Impact

Exploitation of this vulnerability allows for arbitrary PHP code execution on the server, potentially leading to a full compromise of the application or server environment.

Reproduction

The vulnerability can be reproduced by logging into Kiamo with an administrative account. Once authenticated, navigate to the 'Tools' section in the admin interface, where the 'Script' feature is available. This feature can be used to execute PHP scripts on the server. For example, a reverse shell script can be uploaded and executed, initiating a connection back to the attacker's machine and providing interactive shell access on the server.

Remediation

Users are advised to update to Kiamo version 8.4 or later, where this vulnerability has been fixed. In the meantime, access to administrative interfaces should be restricted and the use of the script execution feature monitored.

Added: Apr 9, 2026, 5:05 PM
Updated: Apr 9, 2026, 5:05 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.1
remediation
0.0
relevance
5.6
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.