CVE-2013-10066: Kordil Edms
Critical severity, CVSS 10.0. EPSS: 1.7% chance of exploitation in the next 30 days.
An unauthenticated arbitrary file upload vulnerability exists in Kordil EDMS v2.2.60rc3. The application exposes an upload endpoint (users_add.php) that allows attackers to upload files to the /userpictures/ directory without authentication. This flaw enables remote code execution by uploading a PHP payload and invoking it via a direct HTTP request.
Affected products
- Kordil Edms: version 2.2.60rc3 only
Published 2025-08-05. Last modified 2026-06-16.