Delta Sql 1.8.2 contains an arbitrary file upload...
Critical severity
Unreviewed
Published
May 30, 2026
to the GitHub Advisory Database
•
Updated May 30, 2026
Description
Published by the National Vulnerability Database
May 30, 2026
Published to the GitHub Advisory Database
May 30, 2026
Last updated
May 30, 2026
Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form data. Attackers can upload PHP files with arbitrary content to the upload directory and execute them on the server for remote code execution.
References