EIP-2026-108099
PRE-CVEJob Portal 1.0 - File Upload Restriction Bypass
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-108099. PoCs published by Rafael Pedrero.
AI-analyzed exploit summary This exploit demonstrates a file upload restriction bypass in Job Portal 1.0, allowing authenticated users to upload a malicious PHP file disguised as an image, leading to remote code execution (RCE). The PoC includes a crafted HTTP request that bypasses server-side validation by manipulating the filename parameter while retaining the image content type.
Description
Job Portal 1.0 - File Upload Restriction Bypass
Exploits (1)
This exploit demonstrates a file upload restriction bypass in Job Portal 1.0, allowing authenticated users to upload a malicious PHP file disguised as an image, leading to remote code execution (RCE). The PoC includes a crafted HTTP request that bypasses server-side validation by manipulating the filename parameter while retaining the image content type.