Kunstmaan CMS: MediaBundle extension blacklist bypass allows authenticated administrators to upload executable PHP files leading to remote code execution
The MediaBundle blocks dangerous upload extensions with a blacklist that was matched case-sensitively, while the stored filename was lowercased afterwards. A file uploaded as webshell.pHp therefore bypassed the blacklist and was written to the web-accessible upload directory as webshell.php, where the web server executed it. Any authenticated backend user with access to the media section could obtain remote code execution.