Description
Perch CMS 3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload arbitrary PHP files through the assets management interface. Attackers can upload a malicious .phar file with embedded system command execution capabilities to execute arbitrary commands on the server.
Problem types
Unrestricted Upload of File with Dangerous Type
Product status
Credits
Mirabbas Ağalarov
References
www.exploit-db.com/exploits/51620
www.exploit-db.com/exploits/51620 (ExploitDB-51620)
grabaperch.com/ (Perch Product Webpage)
www.vulncheck.com/...-execution-via-unrestricted-file-upload (VulnCheck Advisory: Perch CMS 3.2 Remote Code Execution via Unrestricted File Upload)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.