top of page
perceptive_background_267k.jpg

Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs…

Published:

29 mei 2026 om 22:00:00

Alert date:

30 mei 2026 om 17:07:56

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage

Delta SQL version 1.8.2 contains a critical arbitrary file upload vulnerability that allows unauthenticated attackers to upload and execute malicious PHP files. The vulnerability exists in the docs_upload.php endpoint which accepts crafted multipart form data without proper validation. Attackers can exploit this flaw by sending POST requests to upload PHP files with arbitrary content to the server's upload directory. Once uploaded, these malicious files can be executed on the server, leading to remote code execution. This vulnerability poses a high security risk as it requires no authentication and provides direct code execution capabilities to attackers.

Technical details

Mitigation steps:

Affected products:

Delta SQL

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page