CVE-2026-56124
phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and embeds the complete JSON-encoded result set in an inline script block, exposing uploader IP addresses, Argon2ID key hashes, internal filenames, and SHA-256 fingerprints.
Published:Jun 29, 2026
Last Modified:Jul 28, 2026
EPS:Jun 29, 2026
EPSS Score:0.00365
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Phpuploader Project
Product
Phpuploader
Phpuploader Project
Phpuploader
Vendor
Shimosyan
Product
Phpuploader
Shimosyan
Phpuploader
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
