CVE-2013-10066: Kordil Edms

Critical severity, CVSS 10.0. EPSS: 1.7% chance of exploitation in the next 30 days.

An unauthenticated arbitrary file upload vulnerability exists in Kordil EDMS v2.2.60rc3. The application exposes an upload endpoint (users_add.php) that allows attackers to upload files to the /userpictures/ directory without authentication. This flaw enables remote code execution by uploading a PHP payload and invoking it via a direct HTTP request.

Affected products

  • Kordil Edms: version 2.2.60rc3 only

Published 2025-08-05. Last modified 2026-06-16.