CVE-2026-15518

MEDIUM

AREA 17 Twill CMS Media Library Insert FileLibraryController.php storeFile unrestricted upload

Title source: cna
STIX 2.1

Description

A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the function FileLibraryController::storeFile of the file src/Http/Controllers/Admin/FileLibraryController.php of the component Media Library Insert Page. Such manipulation of the argument qqfilename leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (5)

Core 5
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-377847 | AREA 17 Twill CMS Media Library Insert FileLibraryController.php storeFile unrestricted upload
https://vuldb.com/vuln/377847
Signature, Permissions Required signature permissions-required
VDB-377847 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/377847/cti
Third Party Advisory third-party-advisory
CVE-2026-15518 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15518
Third Party Advisory third-party-advisory
Submit #849572 | AREA 17 Twill CMS 3.6.0 Unrestricted File Upload
https://vuldb.com/submit/849572

Scores

CVSS v3 4.7
EPSS 0.0025
EPSS Percentile 16.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284 CWE-434
Status published
Products (7)
AREA 17/Twill CMS 3.0
AREA 17/Twill CMS 3.1
AREA 17/Twill CMS 3.2
AREA 17/Twill CMS 3.3
AREA 17/Twill CMS 3.4
AREA 17/Twill CMS 3.5
AREA 17/Twill CMS 3.6.0
Published Jul 13, 2026
Tracked Since Jul 13, 2026