A security flaw has been discovered in diem-project diem up to 5.1.3. The impacted element is an unknown function of the file dmFrontPlugin/lib/dmWidget/media/dmWidgetContentBaseMediaForm.php of the component Widget Editor. Performing a manipulation results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Metrics
Affected Vendors & Products
References
History
Mon, 31 Aug 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in diem-project diem up to 5.1.3. The impacted element is an unknown function of the file dmFrontPlugin/lib/dmWidget/media/dmWidgetContentBaseMediaForm.php of the component Widget Editor. Performing a manipulation results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | diem-project diem Widget Editor dmWidgetContentBaseMediaForm.php unrestricted upload | |
| First Time appeared |
Diem-project
Diem-project diem |
|
| Weaknesses | CWE-284 CWE-434 |
|
| CPEs | cpe:2.3:a:diem-project:diem:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Diem-project
Diem-project diem |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-08-31T10:30:09.492Z
Updated: 2026-08-31T10:30:09.492Z
Reserved: 2026-08-30T16:38:37.555Z
Link: CVE-2026-82679
No data.
Status : Received
Published: 2026-08-31T11:16:40.000
Modified: 2026-08-31T11:16:40.000
Link: CVE-2026-82679
No data.