CVE-2026-25923 | My-Little-Forum mylittleforum 2.5.12 phar Protocol unrestricted upload (GHSA-wr9p-3c3g-78fw)
A vulnerability was found in My-Little-Forum mylittleforum 2.5.12 and classified as critical. Affected by this vulnerability is an unknown functionality of the component phar Protocol Handler. The manipulation results in unrestricted upload.
This vulnerability was named CVE-2026-25923. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.