Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administrative interface. The application does not adequately restrict uploaded file types, allowing malicious files to be uploaded and executed by the server. This condition enables remote code execution under default configurations.
The application does not impose sufficient restrictions on file types uploaded through the administrative interface (CWE-434: Unrestricted Upload of File with Dangerous Type). An attacker with access to an administrator account can upload an executable file (e.g., webshell) to the server. The server then processes and executes the uploaded file, resulting in arbitrary code execution on the server side.
An attacker can gain full control over the server through remote code execution (RCE), which may lead to data breach, system integrity violation, and service availability loss. The attack scope extends beyond the application itself (Scope: Changed).
Explorance Blue must be updated to version 8.14.9 or newer. Details available in the vendor's security bulletin from January 2026 (https://online-help.explorance.com/blue/articles/security-advisories-(january-2026)). Additionally, it is recommended to restrict access to the administrative interface only to trusted networks and apply the principle of least privilege.
Explorance Blue in versions prior to 8.14.9.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HExplorance Blue
APPExplorance< 8.14.9
Related vulnerabilities
SQL Injection bez uwierzytelnienia w Explorance Blue (CVE-2025-57792)
RCE przez podatny upload plików w Explorance Blue (CVE-2025-57795)
Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validati...
Explorance Blue w wersjach poprzedzających 8.14.12 stosuje odwracalne szyfrowanie symetryczne z zakodowanym st...
Multiple Cross Site Scripting (XSS) vulnerabilities in input fields in Explorance Blue 8.1.2 allows attackers ...