The MediaBundle blocks dangerous upload extensions with a blacklist that was matched
case-sensitively, while the stored filename was lowercased afterwards. A file uploaded
as webshell.pHp therefore bypassed the blacklist and was written to the web-accessible
upload directory as webshell.php, where the web server executed it. Any authenticated
backend user with access to the media section could obtain remote code execution.
FileHandler::getFilePath() rewrote blacklisted extensions to .txt using a
case-sensitive regex, and only then lowercased the extension when building the stored
name — so the check ran against the attacker-controlled casing and the normalisation
happened after it.
Two further weaknesses contributed:
php and htaccess, leaving other
server-executable extensions (phtml, php5, phar, shtml, cgi, …) unblocked
regardless of casing.An authenticated user with access to the admin media section can upload a file that the web server executes as PHP. The uploaded file is reachable over HTTP without authentication, giving arbitrary code execution as the web server user.
Fixed in kunstmaan/media-bundle 7.3.2. The extension is now normalised before it is
checked and compared with in_array(); the default blacklist is expanded to the full
set of server-executable extensions; and a new opt-in allowed_extensions option allows
projects to enforce a strict allow-list.
Note that the patch does not rename files already stored on disk. Sites should audit their media upload directory for existing files with an executable extension.
If you cannot upgrade, configure the web server to refuse to execute scripts in the
media upload directory (for example a location block in nginx or php_flag engine off
in Apache).
{
"cwe_ids": [
"CWE-434"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T18:05:38Z",
"nvd_published_at": "2026-10-05T16:17:06Z",
"severity": "HIGH"
}