Sceawere
Vulnerability Detail
CVE-2026-104890UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Kunstmaan CMS Improper Blacklist Validation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- Kunstmaan
- Product
- KunstmaanBundlesCMS
- Attack Type
- CWE-434: Unrestricted Upload of File with Dangerous Type
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Kunstmaan CMS is an open source content management system based on the Symfony framework. Prior to 7.3.2, src/Kunstmaan/MediaBundle/Helper/File/FileHandler.php performs the blacklisted_extensions check case-sensitively in FileHandler::getFilePath and lowercases the stored extension afterward. An authenticated backend user with media access can upload a mixed-case executable extension such as PHP that bypasses the check and is stored in the web-accessible media directory with an executable lowercase extension. The default blacklist also omits several server-executable extension types, allowing the same code-execution impact where the web server executes uploaded files. This issue is fixed in version 7.3.2.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-05T16:17:06.270Z",
"pubdate": "2026-10-05T16:17:06.270Z",
"executiveSummary": "Kunstmaan CMS versions prior to 7.3.2 are susceptible to an arbitrary file upload vulnerability resulting from improper validation of file extensions. The vulnerability stems from a case-sensitive blacklist check followed by a normalization process that converts extensions to lowercase.\nThis flaw allows an authenticated backend user with media management privileges to bypass security filters by uploading files with mixed-case extensions (e.g., .PhP). Upon upload, these files are stored in a web-accessible directory with a normalized, lowercase extension, facilitating remote code execution if the web server is configured to interpret such files as executable scripts.\nThe risk is exacerbated by an insufficient default blacklist that fails to account for various server-executable file types. Successful exploitation grants an attacker the ability to execute arbitrary code within the context of the web server process, potentially leading to full system compromise, data exfiltration, or unauthorized administrative control over the CMS instance.\nThe vulnerability is limited to authenticated backend users with media access; however, the impact is severe, necessitating an immediate upgrade to version 7.3.2 or higher.",
"technicalDetails": "The vulnerability is localized within the src/Kunstmaan/MediaBundle/Helper/File/FileHandler.php component of the Kunstmaan CMS, specifically inside the FileHandler::getFilePath method. The root cause of the flaw is an improper sequence of validation and transformation operations applied to uploaded file extensions.\nIn the vulnerable versions, the application performs a security check against a predefined list of blacklisted extensions using a case-sensitive comparison. An attacker can circumvent this filter by providing a filename with a mixed-case extension, such as 'malicious.PhP'. Because the blacklist check is case-sensitive, it fails to recognize 'PhP' as a prohibited extension, allowing the file to pass the initial security verification.\nFollowing this check, the application processes the filename and normalizes the extension to lowercase. This normalization converts the mixed-case 'PhP' into 'php', which is then stored in a web-accessible directory. Because the underlying web server infrastructure is typically configured to process .php files via the PHP interpreter, the attacker's uploaded script becomes executable.\nFurthermore, the default blacklist implementation in the affected versions is incomplete. It fails to adequately restrict other potentially dangerous server-side executable extensions. This omission allows an attacker to upload files that the web server may parse as executable code depending on the server environment's configuration.\nThe attack flow proceeds as follows: 1) The attacker authenticates as a backend user with sufficient permissions to access the media management functionality. 2) The attacker uploads a crafted payload hidden within a file using a mixed-case extension (e.g., .AsPx, .PhP, .Phtml). 3) The FileHandler::getFilePath method fails the blacklist check due to the case-sensitive string comparison. 4) The CMS normalizes the file extension to lowercase during the save process. 5) The file is written to the web-accessible media directory. 6) The attacker requests the uploaded file directly via a browser, triggering the web server to execute the malicious code.\nThis vulnerability is restricted to users with backend access, but within that scope, it provides a direct path to remote code execution. The impact of such execution includes unauthorized access to system files, escalation of privileges within the CMS, and persistent backdooring of the server environment."
}