CVE 8.7 HIGH

Phar Deserialization leading to Arbitrary File Deletion in my little forum_CVE-2026-25923

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Description

my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application fails to filter the phar:// protocol in URL validation, allowing attackers to upload a malicious Phar Polyglot file (disguised as JPEG) via the image upload feature, trigger Phar deserialization through BBCode [img] tag processing, and exploit Smarty 4.1.0 POP chain to achieve arbitrary file deletion. This vulnerability is fixed in 20260208.1.

AI Analysis

Phar Deserialization vulnerability allowing arbitrary file deletion

Basic Information

ID CVE-2026-25923
Source GitHub_M
Published Feb 9, 2026 at 21:56

Affected Product

Vendor My-Little-Forum
Product mylittleforum
Version < 20260208.1
Affected Versions My-Little-Forum mylittleforum < 20260208.1

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor My-Little-Forum
Product mylittleforum
Version < 20260208.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.