top of page
perceptive_background_267k.jpg

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the termi…

Published:

26 July 2026 at 22:00:00

Alert date:

27 July 2026 at 19:02:54

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities

A critical OS Command Injection vulnerability (CVE-2026-48030) was discovered in Pheditor, a single-file PHP editor and file manager. The flaw affects versions 2.0.1 through 2.0.3 and resides in the terminal action handler. Authenticated users can exploit the vulnerability by injecting shell metacharacters into the 'dir' POST parameter, completely bypassing the TERMINAL_COMMANDS whitelist. Successful exploitation allows full Remote Code Execution (RCE) with web server privileges. The vulnerability requires authentication but poses a severe risk once an attacker has valid credentials. The issue has been patched in version 2.0.4. Users are strongly advised to upgrade immediately to mitigate the risk of full system compromise.

Technical details

Mitigation steps:

Affected products:

Pheditor 2.0.1
Pheditor 2.0.2
Pheditor 2.0.3

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page