/Vulnerability Library

tpadmin <= 1.3.12 - Remote Code Execution

CVE-2026-2113
Verified

Description

yuan1994 tpadmin up to version 1.3.12 is vulnerable to Remote Code Execution via unrestricted file upload in the WebUploader preview component (/public/static/admin/lib/webuploader/0.1.5/server/preview.php). An unauthenticated remote attacker can submit base64-encoded PHP payloads leading to arbitrary code execution with web server privileges.

Severity

Critical

CVSS Score

9.8

Exploit Probability

2%

Affected Product

tpadmin

Published Date

September 10, 2026

Template Author

jankesec

CVE-2026-2113.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-2113
CWE ID:
cwe-434

References

https://github.com/yuan1994/tpadminhttps://nvd.nist.gov/vuln/detail/CVE-2026-2113

Remediation Steps

Delete or restrict access to the preview.php script or upgrade to a patched version.