Snews CMS 1.7 contains an unrestricted file upload...
Critical severity
Unreviewed
Published
Apr 4, 2026
to the GitHub Advisory Database
•
Updated Apr 4, 2026
Description
Published by the National Vulnerability Database
Apr 4, 2026
Published to the GitHub Advisory Database
Apr 4, 2026
Last updated
Apr 4, 2026
Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can upload malicious PHP files through the multipart form-data upload endpoint and execute them by accessing the uploaded file path to achieve remote code execution.
References