Project Pier 0.8.8 and earlier contains an unauthenticated arbitrary file upload vulnerability in tools/upload_file.php. The upload handler fails to validate the file type or enforce authentication, allowing remote attackers to upload malicious PHP files directly into a web-accessible directory. The uploaded file is stored with a predictable suffix and can be executed by requesting its URL, resulting in remote code execution.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 12 Aug 2025 08:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Projectpier Projectpier projectpier | |
| Vendors & Products | Projectpier Projectpier projectpier | 
Fri, 08 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Fri, 08 Aug 2025 18:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Project Pier 0.8.8 and earlier contains an unauthenticated arbitrary file upload vulnerability in tools/upload_file.php. The upload handler fails to validate the file type or enforce authentication, allowing remote attackers to upload malicious PHP files directly into a web-accessible directory. The uploaded file is stored with a predictable suffix and can be executed by requesting its URL, resulting in remote code execution. | |
| Title | Project Pier <= 0.8.8 Arbitrary File Upload RCE | |
| Weaknesses | CWE-434 | |
| References |  | 
 | 
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-08-08T18:51:11.960Z
Reserved: 2025-08-07T19:03:18.667Z
Link: CVE-2012-10036
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-08-08T18:51:00.834Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-08-08T19:15:33.683
Modified: 2025-08-08T20:30:18.180
Link: CVE-2012-10036
 Redhat
                        Redhat
                    No data.