top of page
perceptive_background_267k.jpg

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password a…

Published:

26 July 2026 at 22:00:00

Alert date:

27 July 2026 at 21:04:07

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

Pheditor, a single-file PHP-based file editor and manager, contains a hardcoded default password 'admin' (stored as a SHA-512 hash) in versions 2.0.1 through 2.0.5. There is no mechanism to enforce a password change upon first login, leaving deployments using default credentials fully exposed. An attacker exploiting this weakness gains unrestricted access to file editing, file upload, and terminal features. This effectively enables arbitrary file read/write operations and remote code execution on the affected server. The vulnerability is particularly dangerous because it requires no exploitation sophistication beyond using a known default credential. The issue affects any deployment that has not manually changed the default password. A patch has been released in version 2.0.6 which addresses this hardcoded credential issue.

Technical details

Mitigation steps:

Affected products:

Pheditor 2.0.1
Pheditor 2.0.2
Pheditor 2.0.3
Pheditor 2.0.4
Pheditor 2.0.5

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page