CVE-2026-2226

A vulnerability has been found in DouPHP up to 1.9. This issue affects some unknown processing of the file /admin/file.php of the component ZIP File Handler. Such manipulation of the argument sql_filename leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://github.com/pengchengwangli/MyCVE/issues/2 Exploit Issue Tracking Mitigation Third Party Advisory
https://vuldb.com/?ctiid.344943 Permissions Required VDB Entry
https://vuldb.com/?id.344943 Third Party Advisory VDB Entry
https://vuldb.com/?submit.753441 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:douco:douphp:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-09 10:15

Updated : 2026-02-27 18:10


NVD link : CVE-2026-2226

Mitre link : CVE-2026-2226

CVE.ORG link : CVE-2026-2226


JSON object : View

Products Affected

douco

  • douphp
CWE
CWE-284

Improper Access Control

CWE-434

Unrestricted Upload of File with Dangerous Type