CVE-2026-92247

MEDIUM Status: Received

CVSS Scores

CVSS v3.x Base Score
4.7
MEDIUM
CVSS v2 Base Score
5.8
MEDIUM

Description

A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename of the file admin/file-manager.php of the component Admin File Manager. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 1.3.5 is able to mitigate this issue. It is suggested to upgrade the affected component.

Published
September 16, 2026 3:17 AM
Last Modified
September 16, 2026 3:17 AM
Source
[email protected]

Weaknesses (CWE)

CWE-284 CWE-434

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.