PT-2026-83778 · Diem · Diem
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
diem-project diem versions prior to 5.1.4
Description
A flaw in the Widget Editor component allows for unrestricted upload of files. This issue occurs within an unknown function located in the file
dmFrontPlugin/lib/dmWidget/media/dmWidgetContentBaseMediaForm.php and can be triggered remotely.Recommendations
Update diem-project diem to version 5.1.4 or later.
As a temporary mitigation, restrict access to the
dmFrontPlugin/lib/dmWidget/media/dmWidgetContentBaseMediaForm.php file.Exploit
Fix
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Diem