GHSA-p279-5wcv-45vq: Malicious File Upload

Published Oct 7, 2026
·
Updated

Summary

The MediaBundle blocks dangerous upload extensions with a blacklist that was matched case-sensitively, while the stored filename was lowercased afterwards. A file uploaded as webshell.pHp therefore bypassed the blacklist and was written to the web-accessible upload directory as webshell.php, where the web server executed it. Any authenticated backend user with access to the media section could obtain remote code execution.

Details

FileHandler::getFilePath() rewrote blacklisted extensions to .txt using a case-sensitive regex, and only then lowercased the extension when building the stored name — so the check ran against the attacker-controlled casing and the normalisation happened after it.

Two further weaknesses contributed:

The default blacklist contained only php and htaccess, leaving other server-executable extensions (phtml, php5, phar, shtml, cgi, …) unblocked regardless of casing. Configured blacklist values were interpolated into the regex unescaped.

Impact

An authenticated user with access to the admin media section can upload a file that the web server executes as PHP. The uploaded file is reachable over HTTP without authentication, giving arbitrary code execution as the web server user.

Patches

Fixed in kunstmaan/media-bundle 7.3.2. The extension is now normalised before it is checked and compared with inarray(); the default blacklist is expanded to the full set of server-executable extensions; and a new opt-in allowedextensions option allows projects to enforce a strict allow-list.

Note that the patch does not rename files already stored on disk. Sites should audit their media upload directory for existing files with an executable extension.

Workarounds

If you cannot upgrade, configure the web server to refuse to execute scripts in the media upload directory (for example a location block in nginx or phpflag engine off in Apache).

Affected Software

2 affected componentsFixes available
composer/kunstmaan/bundles-cms<7.3.2
7.3.2
composer/kunstmaan/media-bundle<7.3.2
7.3.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/kunstmaan/bundles-cms to a version that resolves this vulnerability.

    Fixed in 7.3.2
  2. Upgrade

    Upgrade composer/kunstmaan/media-bundle to a version that resolves this vulnerability.

    Fixed in 7.3.2
  3. Upgrade

    Upgrade kunstmaan/media-bundle to a version that resolves this vulnerability.

    Fixed in 7.3.2
  4. Configuration

    Configure the web server to refuse to execute scripts in the media upload directory, such as using a location block in nginx or php_flag engine off in Apache.

    MediaBundle media upload directory server-side script execution = disabled
  5. Configuration

    Enable the opt-in allowed_extensions option to enforce a strict allow-list for uploaded file extensions.

    kunstmaan/media-bundle allowed_extensions = strict allow-list
  6. Operational

    Audit the media upload directory for existing files with an executable extension, because the patch does not rename files already stored on disk.

Event History

Oct 7, 2026
Advisory Published
via GitHub·06:05 PM
Data Sourced
via GitHub·06:05 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who can realistically exploit this issue?

An authenticated backend user who has access to the admin media section can exploit it. The uploaded file can then be reached over HTTP without authentication.

2

Is the default blacklist sufficient to prevent executable uploads?

No. The default blacklist includes only php and htaccess, leaving other potentially server-executable extensions, such as phtml, php5, phar, shtml, and cgi, unblocked regardless of letter casing.

3

Does adding custom blacklist entries avoid the problem?

Custom blacklist values are interpolated into the matching regular expression without escaping. This means configured values can affect the regex rather than being treated strictly as literal extensions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203