CVE-2026-56124
HIGHphpUploader < 2.0.2 Unauthenticated Database Exposure via index model
Title source: cnaDescription
phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and embeds the complete JSON-encoded result set in an inline script block, exposing uploader IP addresses, Argon2ID key hashes, internal filenames, and SHA-256 fingerprints.
References (4)
Core 4
Core References
Release Notes release-notes
Release Notes
https://github.com/shimosyan/phpUploader/releases/tag/v2.0.2
Patch patch
Patch Commit
https://github.com/shimosyan/phpUploader/commit/45dc4f1c9a2de5ade427deebad0148834c0e8c50
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/phpuploader-unauthenticated-database-exposure-via-index-model
Scores
CVSS v3
7.5
EPSS
0.0037
EPSS Percentile
29.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-359
CWE-497
Status
published
Products (1)
shimosyan/phpUploader
< 2.0.2
Published
Jun 29, 2026
Tracked Since
Jun 29, 2026