top of page
perceptive_background_267k.jpg

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the termi…

Published:

27 July 2026 at 00:00:00

Alert date:

27 July 2026 at 23:04:07

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities

A critical OS Command Injection vulnerability (CVE-2026-48030) was discovered in Pheditor, a single-file PHP editor and file manager. The flaw exists in versions 2.0.1 through 2.0.3 within the terminal action handler. Authenticated attackers can inject shell metacharacters into the 'dir' POST parameter to execute arbitrary OS commands. The vulnerability completely bypasses the TERMINAL_COMMANDS whitelist security control. Successful exploitation results in full Remote Code Execution (RCE) with web server privileges. The issue has been patched in version 2.0.4. Users are strongly advised to upgrade immediately.

Technical details

Mitigation steps:

Affected products:

Pheditor 2.0.1
Pheditor 2.0.2
Pheditor 2.0.3

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page