EIP-2026-107512
PRE-CVEGRR Système de Gestion et de Réservations de Ressources 3.0.0-RC1 - Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107512. PoCs published by kmkz.
AI-analyzed exploit summary This exploit demonstrates an authenticated RCE vulnerability in GRR <= 3.0.0-RC1 by bypassing file upload filters via a double extension (e.g., backdoor.php.jpg) to upload a malicious PHP file, which is then renamed to logo.php with 0666 permissions, allowing arbitrary code execution.
Description
GRR Système de Gestion et de Réservations de Ressources 3.0.0-RC1 - Arbitrary File Upload
Exploits (1)
This exploit demonstrates an authenticated RCE vulnerability in GRR <= 3.0.0-RC1 by bypassing file upload filters via a double extension (e.g., backdoor.php.jpg) to upload a malicious PHP file, which is then renamed to logo.php with 0666 permissions, allowing arbitrary code execution.