CVE-2026-6211 PUBLISHED

Arbitrary File Upload in Global IT's WEOLL

Assigner: TR-CERT
Reserved: 13.04.2026 Published: 12.06.2026 Updated: 12.06.2026

Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects WEOLL: from 2.0.9 before 3.2.45.33.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
CVSS Score: 8.7

Product Status

Vendor Global IT Informatics Services Inc.
Product WEOLL
Versions Default: unaffected
  • affected from 2.0.9 to 3.2.45.33 (excl.)

Credits

  • Hamza Metin GERDAN finder

References

Problem Types

  • CWE-434 Unrestricted upload of file with dangerous type CWE

Impacts

  • CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs