🔐 CVE Alert

CVE-2013-10066

UNKNOWN 0.0

Kordil EDMS v2.2.60rc3 Unauthenticated Arbitrary File Upload

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

An unauthenticated arbitrary file upload vulnerability exists in Kordil EDMS v2.2.60rc3. The application exposes an upload endpoint (users_add.php) that allows attackers to upload files to the /userpictures/ directory without authentication. This flaw enables remote code execution by uploading a PHP payload and invoking it via a direct HTTP request.

CWE CWE-434
Vendor kordil
Product edms
Published Aug 5, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for kordil edms

Be the first to know when new unknown vulnerabilities affecting kordil edms are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Kordil / EDMS
2.2.60rc3

References

NVD ↗ CVE.org ↗ EPSS Data ↗
raw.githubusercontent.com: https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/kordil_edms_upload_exec.rb exploit-db.com: https://www.exploit-db.com/exploits/24547 juniper.net: https://www.juniper.net/us/en/threatlabs/ips-signatures/detail.APP:MSF-KORDIL-EDMS-AFU.html sourceforge.net: https://sourceforge.net/projects/kordiledms/ vulncheck.com: https://www.vulncheck.com/advisories/kordil-edms-unauth-arbitrary-file-upload

Credits

bcoles