High severity7.2NVD Advisory· Published Oct 11, 2021· Updated Jun 17, 2026
CVE-2021-40188
CVE-2021-40188
Description
PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability. The File Manager function in admin panel does not filter all PHP extensions such as ".php, .php7, .phtml, .php5, ...". An attacker can upload a malicious file and execute code on the server.
Affected products
3cpe:2.3:a:php-fusion:phpfusion:9.03.110:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:php-fusion:phpfusion:9.03.110:*:*:*:*:*:*:*
- (no CPE)range: =9.03.110
- PHPFusion/PHPFusiondescription
Patches
Vulnerability mechanics
References
1- github.com/PHPFusion/PHPFusion/issues/2372nvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.