HIGH
ARMBot Unrestricted File Upload via upload.php
Published Mar 11, 2026
8.7
HIGHCVSS 4.0
EPSS 0.72%
Description
ARMBot contains an unrestricted file upload vulnerability in upload.php that allows unauthenticated attackers to upload arbitrary files by manipulating the file parameter with path traversal sequences. Attackers can upload PHP files with traversal payloads ../public_html/ to write executable code to the web root and achieve remote code execution.
Affected products
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-19760 Advisory
- https://www.exploit-db.com/exploits/47209 exploit
- https://www.vulncheck.com/advisories/armbot-unrestricted-file-upload-via-upload-php third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-19760 | Advisory | |
| https://www.exploit-db.com/exploits/47209 | exploit | |
| https://www.vulncheck.com/advisories/armbot-unrestricted-file-upload-via-upload-php | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Mar 11, 2026
Updated Apr 7, 2026
Reserved Feb 23, 2026
Link CVE-2019-25480
CISA Vulnrichment
Updated Mar 11, 2026
ENISA EUVD
EUVD-2019-19760 Assigner VulnCheck
Published Mar 11, 2026
Updated Apr 7, 2026
Exploited since n/a
Link EUVD-2019-19760