๐Ÿ” CVE Alert

CVE-2012-10050

UNKNOWN 0.0

CuteFlow <= 2.11.2 Arbitrary File Upload RCE

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

CuteFlow version 2.11.2 and earlier contains an arbitrary file upload vulnerability in the restart_circulation_values_write.php script. The application fails to validate or restrict uploaded file types, allowing unauthenticated attackers to upload arbitrary PHP files to the upload/___1/ directory. These files are then accessible via the web server, enabling remote code execution.

CWE CWE-434
Vendor cuteflow.org
Product cuteflow
Published Aug 8, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for cuteflow.org cuteflow

Be the first to know when new unknown vulnerabilities affecting cuteflow.org cuteflow are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

CuteFlow.org / CuteFlow
* โ‰ค 2.11.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
web.archive.org: https://web.archive.org/web/20120729071444/http://www.cuteflow.org/ raw.githubusercontent.com: https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/cuteflow_upload_exec.rb exploit-db.com: https://www.exploit-db.com/exploits/20111 web.archive.org: http://web.archive.org/web/20210922054637/https://itsecuritysolutions.org/2012-07-01-CuteFlow-2.11.2-multiple-security-vulnerabilities/ sourceforge.net: https://sourceforge.net/projects/cuteflow/ vulncheck.com: https://www.vulncheck.com/advisories/cuteflow-arbitrary-file-upload-rce

Credits

bcoles