ZeroHour

CVE-2026-84063

niche

Unrestricted File Upload in BurgerEditor 3.2.0–3.4.0 Enables PHP Code Execution

CVSS 4.0
8.5 high
EPSS
<1%p37
Published
()
Modified
AI analysis

BurgerEditor versions 3.2.0 through 3.4.0 are affected by an unrestricted file upload flaw (CWE-434) that allows files with dangerous types, such as PHP scripts, to be uploaded without restriction. The flaw is triggered when an attacker who is able to log in to the product abuses the upload functionality to place an arbitrary file on the server. By uploading a malicious PHP file, the attacker can potentially achieve arbitrary PHP code execution on the host, effectively gaining remote code execution under the web server's privileges. Any deployment running BurgerEditor 3.2.0 through 3.4.0 is affected, and the CVSS 4.0 score of 8.5 (high) reflects that exploitation requires an authenticated attacker with elevated privileges. There is currently no public proof of concept, the flaw is not listed in CISA's KEV catalog, and no in-the-wild exploitation has been reported.

What to do: Upgrade BurgerEditor to a fixed release outside the affected 3.2.0–3.4.0 range as specified in the vendor/JPCERT advisory. Until patched, restrict upload-capable accounts, enforce strict allowlists on uploaded file types, and block PHP execution in upload directories. Audit upload directories for unexpected or recently added .php files that could indicate prior exploitation.

Affected
BurgerEditor project BurgerEditor3.2.0 through 3.4.0
Estimated exposure
nichelikely on the order of thousands of deployments at most (specialized niche editor plugin with no published install metrics) — No public install counts are available, but BurgerEditor is a specialized editor component with adoption concentrated in a small, primarily Japanese ecosystem, so exposure is estimated to be far below mass-scale plugin/adoption figures;…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type. If this vulnerability is exploited, an arbitrary file may be uploaded by an attacker who can log in to the product, potentially allowing arbitrary PHP code to be executed may be caused.

Weakness
CWE-434
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.