Description
A vulnerability was found in iJason-Liu Books_Manager up to 298ba736387ca37810466349af13a0fdf828e99c. This vulnerability affects unknown code of the file controllers/books_center/upload_bookCover.php. Performing a manipulation of the argument book_cover results in unrestricted upload. The attack may be initiated remotely. The exploit has been made public and could be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available.
Problem types
Product status
Timeline
| 2026-01-26: | Advisory disclosed |
| 2026-01-26: | VulDB entry created |
| 2026-01-28: | VulDB entry last update |
Credits
y1fan (VulDB User)
References
vuldb.com/?id.342874 (VDB-342874 | iJason-Liu Books_Manager upload_bookCover.php unrestricted upload)
vuldb.com/?ctiid.342874 (VDB-342874 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.736971 (Submit #736971 | https://github.com/iJason-Liu/Books_Manager Books_Manager 1.0 File Upload)
blog.y1fan.work/2026/01/13/任意文件上传getshell/