CVE-2026-96513: Neethuharii CafeManagement AddProductCode.php unrestricted upload
A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown processing of the file AddProductCode.php. The manipulation of the argument image results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is remotely exploitable over the network and requires no privileges or user interaction. A public exploit is available, increasing the likelihood of attempted attacks.
Which releases are affected or fixed?
Affected and updated release versions are not disclosed because the product uses a rolling-release delivery model. The available information does not identify a fixed version.
What component should defenders prioritize for investigation?
Prioritize the AddProductCode.php endpoint and its handling of the image argument. The reported issue is an unrestricted file upload condition in that processing path.
Has the vendor provided remediation guidance?
No vendor response or remediation guidance is reported. The vendor was contacted before disclosure but did not respond.