Back

CRITICAL

CuteFlow <= 2.11.2 Arbitrary File Upload RCE

Published Aug 8, 2025

Description

CuteFlow version 2.11.2 and earlier contains an arbitrary file upload vulnerability in the restart_circulation_values_write.php script. The application fails to validate or restrict uploaded file types, allowing unauthenticated attackers to upload arbitrary PHP files to the upload/___1/ directory. These files are then accessible via the web server, enabling remote code execution.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 8, 2025
Updated May 15, 2026
Reserved Aug 8, 2025
CISA Vulnrichment
Updated Aug 8, 2025
NVD
Status Deferred
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a