EIP-2026-107077
PRE-CVEFestOS 2.3c - 'upload.php' Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107077. PoCs published by KedAns-Dz.
AI-analyzed exploit summary The code describes an arbitrary file upload vulnerability in FestOS 2.3c, where the application fails to sanitize user input, allowing attackers to upload and execute arbitrary code via the TinyMCE plugin's upload.php endpoint.
Description
FestOS 2.3c - 'upload.php' Arbitrary File Upload
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by KedAns-Dz · textwebappsphp
https://www.exploit-db.com/exploits/35713
The code describes an arbitrary file upload vulnerability in FestOS 2.3c, where the application fails to sanitize user input, allowing attackers to upload and execute arbitrary code via the TinyMCE plugin's upload.php endpoint.
Classification
Writeup 80%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:
FestOS 2.3c
No auth needed
Prerequisites:
Access to the vulnerable endpoint · Ability to send HTTP requests to the target
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026