


Perceptive Security
SOC/SIEM Consultancy

Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs…
Published:
29 mei 2026 om 22:00:00
Alert date:
30 mei 2026 om 17:07:56
Source:
nvd.nist.gov
Web Technologies, Database & Storage
Delta SQL version 1.8.2 contains a critical arbitrary file upload vulnerability that allows unauthenticated attackers to upload and execute malicious PHP files. The vulnerability exists in the docs_upload.php endpoint which accepts crafted multipart form data without proper validation. Attackers can exploit this flaw by sending POST requests to upload PHP files with arbitrary content to the server's upload directory. Once uploaded, these malicious files can be executed on the server, leading to remote code execution. This vulnerability poses a high security risk as it requires no authentication and provides direct code execution capabilities to attackers.
Technical details
Mitigation steps:
Affected products:
Delta SQL
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25412
http://deltasql.sourceforge.net/
http://deltasql.sourceforge.net/deltasql/
https://sourceforge.net/projects/deltasql/files/latest/download
https://www.exploit-db.com/exploits/45685
https://www.vulncheck.com/advisories/delta-sql-arbitrary-file-upload-via-docs-upload-php
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
