A vulnerability was detected in EyouCMS up to 1.7.1. This issue affects the function edit_adminlogo of the file application/admin/controller/Index.php. Performing a manipulation of the argument filename results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Sun, 19 Apr 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in EyouCMS up to 1.7.1. This issue affects the function edit_adminlogo of the file application/admin/controller/Index.php. Performing a manipulation of the argument filename results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | EyouCMS Index.php edit_adminlogo unrestricted upload | |
| First Time appeared |
Eyoucms
Eyoucms eyoucms |
|
| Weaknesses | CWE-284 CWE-434 |
|
| CPEs | cpe:2.3:a:eyoucms:eyoucms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Eyoucms
Eyoucms eyoucms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-19T07:15:11.267Z
Reserved: 2026-04-18T15:58:33.191Z
Link: CVE-2026-6561
No data.
Status : Received
Published: 2026-04-19T08:16:26.113
Modified: 2026-04-19T08:16:26.113
Link: CVE-2026-6561
No data.
OpenCVE Enrichment
Updated: 2026-04-19T08:30:15Z