tpadmin <= 1.3.12 - Remote Code Execution
CVE-2026-2113
Verified
Description
yuan1994 tpadmin up to version 1.3.12 is vulnerable to Remote Code Execution via unrestricted file upload in the WebUploader preview component (/public/static/admin/lib/webuploader/0.1.5/server/preview.php). An unauthenticated remote attacker can submit base64-encoded PHP payloads leading to arbitrary code execution with web server privileges.
Severity
Critical
CVSS Score
9.8
Exploit Probability
2%
Affected Product
tpadmin
Published Date
September 10, 2026
Template Author
jankesec
CVE-2026-2113.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-2113
CWE ID:
cwe-434
Remediation Steps
Delete or restrict access to the preview.php script or upgrade to a patched version.