What is CVE-2026-48030?
CVE-2026-48030 is an OS Command Injection vulnerability found in Pheditor, a single-file PHP editor. Authenticated attackers can execute arbitrary OS commands by injecting shell metacharacters into the 'dir' POST parameter via the terminal action handler in versions from 2.0.1 to before 2.0.4. Immediate update to version 2.0.4 is required.
Azərbaycanca: CVE-2026-48030, PHP-də yazılmış Pheditor fayl redaktorunda aşkar edilmiş OS Command Injection zəifliyidir. 2.0.1-dən 2.0.4-ə qədər versiyalarda autentifikasiya olunmuş istənilən istifadəçi terminal əməliyyatı zamanı 'dir' parametrinə shell metacharacters əlavə edərək özbaşına əmrlər icra edə bilər. Təcili olaraq 2.0.4 versiyasına yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
What software is affected by CVE-2026-48030?
CVE-2026-48030 is an OS Command Injection vulnerability found in Pheditor, a single-file PHP editor.
Is authentication required to exploit this OS Command Injection vulnerability?
Yes, authenticated attackers can exploit this vulnerability by injecting shell metacharacters into the 'dir' POST parameter via the terminal action handler.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.