PT-2026-83992 · Wallos · Wallos
CVE-2026-61639
·
Published
2026-08-31
·
Updated
2026-09-01
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Wallos versions prior to 4.9.6
Description
An issue exists where the application fails to validate entry names for directory traversal sequences when processing zip files. An administrator can upload a specially crafted zip archive to the 'POST /endpoints/db/restore.php' endpoint, which uses the
ZipArchive::extractTo() function. By including entries with ../ sequences, such as logos/../../endpoints/shell.php, an attacker can write a webshell directly into the webroot. The existing extension filter is ineffective because it only applies to the logo copy step after the extraction has already occurred.Recommendations
Update to version 4.9.6.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wallos