CVE-2026-84063
6.5
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Summary
BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type. If this vulnerability is exploited, an arbitrary file may be uploaded by an attacker who can log in to the product, potentially allowing arbitrary PHP code to be executed may be caused.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| D-ZERO CO.,LTD. | BurgerEditor | 3.2.0 through 3.4.0 | affected |
| D-ZERO CO.,LTD. | BurgerEditor | 2.28.0 through 2.30.0 | affected |
Weaknesses
- CWE-434: Unrestricted upload of file with dangerous type
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.