CVE-2025-51511: 
PHP vulnerability analysis and mitigation

Overview

CVE-2025-51511 is an unrestricted file upload vulnerability (CWE-434) in Cadmium CMS v.0.4.9, a PHP-based content management system. The flaw exists in the /admin/content/filemanager/uploads endpoint and allows attackers to upload arbitrary files — including PHP web shells — without proper validation or authentication controls. It was disclosed on December 23, 2025, and affects only version 0.4.9 of the Composer package cadmium-org/cadmium-cms. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) as assessed by CISA-ADP (Github Advisory, GitHub Issue).

Technical details

The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type): the file manager endpoint /admin/content/filemanager/uploads fails to validate uploaded file types or enforce authentication, allowing any network-accessible attacker to upload executable PHP files. According to the public issue report, an attacker can upload an image file containing malicious PHP code and then rename it with a .php extension, making it directly accessible and executable via the web server at a path such as http://target.com/uploads/phpinfo.php. No complex prerequisites, user interaction, or elevated privileges are required for exploitation (GitHub Issue, Github Advisory).

Impact

Successful exploitation enables full remote code execution (RCE) on the affected server, giving an attacker the ability to execute arbitrary commands under the web server's process context. This results in complete compromise of confidentiality (access to sensitive data, credentials, and configuration files), integrity (modification or deletion of system and application files), and availability (service disruption or ransomware deployment). The network-accessible nature of the vulnerability with no authentication requirement means any internet-facing Cadmium CMS v.0.4.9 instance is immediately at risk, and a foothold could be leveraged for lateral movement within the hosting environment (Github Advisory, GitHub Issue).

Exploitability

A proof-of-concept (PoC) exploit has been publicly documented in the GitHub issue tracker for the Cadmium CMS project, demonstrating the upload and execution of a PHP web shell (GitHub Issue). There is no confirmed evidence of active in-the-wild exploitation or threat actor attribution at this time (Github Advisory). The EPSS score is approximately 0.056% (0.2% per GitHub Advisory), placing it in the 42nd percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Cadmium CMS instances running version 0.4.9 using search engines (e.g., Shodan, Censys) or by checking the CMS version via publicly accessible pages or composer.json.
  2. Access the upload endpoint: Navigate directly to http://target.com/admin/content/filemanager/uploads — no authentication is required to interact with this endpoint.
  3. Craft a malicious file: Prepare a PHP web shell (e.g., <?php system($_GET['cmd']); ?>) embedded within or disguised as an image file (e.g., shell.jpg).
  4. Upload the malicious file: Submit the crafted file to the /admin/content/filemanager/uploads endpoint via an HTTP POST request.
  5. Rename the file: Use the file manager's rename functionality (if available) or re-upload with a .php extension to change the file name to something like shell.php.
  6. Execute the web shell: Access the uploaded file directly at http://target.com/uploads/shell.php?cmd=id to achieve remote code execution on the server (GitHub Issue).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to /admin/content/filemanager/uploads from external or unknown IP addresses; HTTP GET requests to /uploads/*.php files, particularly with query parameters like cmd, exec, or c.
  • File System: Presence of .php files in the /uploads/ directory (e.g., shell.php, phpinfo.php, cmd.php); files with PHP content disguised with image extensions (e.g., .jpg, .png) in the uploads directory.
  • Logs: Web server access logs showing POST requests to /admin/content/filemanager/uploads followed by GET requests to /uploads/<filename>.php; PHP error logs showing execution of system commands or unusual function calls.
  • Process: Unusual child processes spawned by the PHP-FPM or Apache process (e.g., bash, curl, wget, python, nc) indicating command execution via the web shell (GitHub Issue).

Mitigation and workarounds

The GitHub Advisory Database notes that no patched version has been formally released for the cadmium-org/cadmium-cms Composer package (all versions ≤ 0.4.9 are listed as affected), and the project appears to be in an unmaintained state (Github Advisory). Organizations should immediately restrict network-level access to the /admin/content/filemanager/uploads endpoint using a Web Application Firewall (WAF) or firewall rules. Additional mitigations include: disabling PHP execution in the /uploads/ directory via server configuration (e.g., Apache .htaccess or Nginx location blocks), monitoring the uploads directory for unexpected .php files, and considering migration to an actively maintained CMS if a vendor patch is not forthcoming.

Community reactions

The vulnerability was covered by The Hacker Wire, which published an article titled "Critical Arbitrary File Upload in Cadmium CMS 0.4.9 Exposes Systems to RCE" (The Hacker Wire). Social media posts on Bluesky and Mastodon (infosec.exchange) also highlighted the disclosure shortly after publication. Community reaction has been limited given the niche nature of the affected software, but the critical CVSS score and unauthenticated RCE potential drew attention from vulnerability tracking services including VulDB, Vulners, and CVEFeed.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management