Skip to content
 
 

Latest commit

 

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

CVE-2026-38526 | Authenticated Unrestricted PHP File Upload via TinyMCE

Description

CVE-2026-38526 is a critical authenticated file upload vulnerability leading to remote code execution
affecting Webkul Krayin CRM v2.2.x. The vulnerability exists in the TinyMCE media upload endpoint /admin/tinymce/upload, which fails to validate uploaded file types. An authenticated attacker can upload a malicious PHP file and execute arbitrary commands on the server.

  • CVE: CVE-2026-38526
  • CVSS Score: 9.9 (Critical)
  • CWE: CWE-434 - Unrestricted Upload of File with Dangerous Type
  • Affected Version: Krayin Laravel CRM v2.2.x
  • Vendor: Webkul

Technical Details

The /admin/tinymce/upload endpoint accepts multipart file uploads for the TinyMCE rich text editor. The server performs no validation on the uploaded file type or extension, allowing an attacker to upload a PHP webshell. The uploaded file is stored in a web-accessible directory (/storage/tinymce/), meaning a subsequent GET request to the file path causes the PHP interpreter to execute the payload.

Attack flow:

  1. Authenticate to Krayin CRM with any valid account
  2. Upload a PHP webshell to /admin/tinymce/upload with spoofed Content-Type: image/jpeg
  3. Server responds with the uploaded file's URL
  4. Print uploaded file path

Requirements

  • Python 3.x
  • requests library (pip install requests)
  • Valid credentials for the target Krayin CRM instance

Usage

Flag Description
-t Target URL
-u Login email address
-p Login password
-f File that will be uploaded to the target
git clone https://github.com/NathanHimself/CVE-2026-38526-PoC
cd CVE-2026-38526-PoC
chmod +x exploit.py
python3 exploit.py -t <target URL> -u <email> -p <password> -f <file>

Disclaimer

This tool is for authorized penetration testing and educational purposes only. Do not use against systems you do not have explicit permission to test. The author assumes no responsibility and shall not be held liable for any misuse, damage, or illegal activity arising from the use of this PoC.

References

Credit

This is a forked repository that I've modified to suit my needs. credit goes to the original author.

About

CVE-2026-38526 | Krayin CRM v2.2.x Authenticated Unrestricted PHP File Upload via TinyMCE

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages