Exploitation Summary
EIP tracks 1 public exploit for CVE-2026-53691. PoCs published by HermesNA-1.
AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-53691, an unrestricted file upload vulnerability in Redeight CMS 1.0. The code includes metadata and placeholder methods but lacks actual exploit implementation, referencing an external link for details.
Description
An Unrestricted File Upload vulnerability in Redeight CMS version 1.0 allows authenticated attackers to achieve Remote Code Execution via the POST "/admin/index.php?module=pages&mode=FileAdd" endpoint. The application fails to validate file extensions and MIME types, permitting the upload of arbitrary PHP scripts to the publicly accessible "/uploads/files/" directory where they can be executed directly by the web server.
Exploits (1)
This repository contains an auto-generated stub module for CVE-2026-53691, an unrestricted file upload vulnerability in Redeight CMS 1.0. The code includes metadata and placeholder methods but lacks actual exploit implementation, referencing an external link for details.
References (1)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X