GHSA-mcxq-54f4-mmx5

Suggest an improvement
Source
https://github.com/advisories/GHSA-mcxq-54f4-mmx5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-mcxq-54f4-mmx5/GHSA-mcxq-54f4-mmx5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mcxq-54f4-mmx5
Aliases
Published
2025-12-02T21:31:31Z
Modified
2025-12-03T17:43:38Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
  • 6.8 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
FeehiCMS Has a Remote Code Execution via Unrestricted File Upload in Ad Management
Details

FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1 allows authenticated remote attackers to upload files that the server later executes (or stores in an executable location) without sufficient validation, sanitization, or execution restrictions. An authenticated remote attacker can upload a crafted PHP file and cause the application or web server to execute it, resulting in remote code execution (RCE).

Database specific
{
    "cwe_ids":  [
        "CWE-20",
        "CWE-77"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-12-03T16:59:21Z",
    "nvd_published_at":  "2025-12-02T21:15:53Z",
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / feehi/cms

Package

Name
feehi/cms
Purl
pkg:composer/feehi/cms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.1.1

Affected versions

0.*
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
1.*
1.0.0alpha1
1.0.0alpha2
1.0.0-alpha3
1.0.0beta1
1.0.0beta2
1.0.0beta3
1.0.0rc1
1.0.0rc2
2.*
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.4.1
2.0.5
2.0.5.1
2.0.6
2.0.7
2.0.7.1
2.0.8
2.0.8.1
2.1.0-beta
2.1.0-beta2
2.1.0
2.1.0.1
2.1.0.2
2.1.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-mcxq-54f4-mmx5/GHSA-mcxq-54f4-mmx5.json"