HIGHVulnerability
Verified
Global
CISA KEV: iCagenda iCagenda — iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
·Source: CISA KEV
Updated:
Executive Summary
iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Analysis
iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution. Added to CISA Known Exploited Vulnerabilities catalog on 2026-07-10. Remediation due: 2026-07-13.