Back Redpacketsecurity CVE Alert: CVE-2026-95499 – JosephChuks – php-file-manager-with-code
A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of the argument files can lead to unrestricted upload. The attack can be executed remotely. The vendor was contacted early this disclosure but did not respond in any way.
Treat this as a high-priority exposure for internet-facing deployments, although current enrichment indicates no confirmed exploitation and no KEV or EPSS prioritisation data is supplied.
The weakness can allow an unauthenticated remote party to place attacker-controlled content on the server, potentially enabling website tampering, malware hosting, data exposure or service disruption. Its automatable nature makes opportunistic scanning plausible, while the stated partial impact suggests meaningful compromise even without broader system or security-boundary effects.
### Most likely attack path
An attacker can reach the application remotely with low complexity, without credentials or user interaction, and submit a crafted upload through the affected file-management function. They would then seek execution or direct access to the uploaded content, depending on server configuration; scope is unchanged, so lateral movement is not inherent but could follow if the host has trusted access to other systems.
### Who is most exposed
Publicly accessible installations used for web administration, content publishing, shared hosting or customer file exchange are most at risk, particularly where uploaded files reside beneath executable web paths.
Review web logs for unusual upload requests and unexpected multipart parameters.
Alert on newly created scripts or executable content in upload directories.
Hunt for subsequent requests to recently uploaded filenames.
Check for anomalous child processes spawned by the web server.
Compare file-manager activity with authenticated administrator sessions.
### Mitigation and prioritisation
Apply a vendor-approved fixed release or remove the component if no fix exists.
Immediately restrict access by VPN, allow-listing or upstream authentication.
Disable script execution and server-side interpretation in upload locations.
Enforce extension, MIME, content-signature and storage-path controls.
Treat as urgent change work; test publishing workflows and preserve rollback capability.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
