Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-53971

Опубликовано: 22 дек. 2025
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functionality. Attackers can upload a PHP file with arbitrary code to the /files/Messages/ directory and execute it directly through the generated file path.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:webtareas_project:webtareas:2.4:-:*:*:*:*:*:*

EPSS

Процентиль: 16%
0.00052
Низкий

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
github
около 2 месяцев назад

WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functionality. Attackers can upload a PHP file with arbitrary code to the /files/Messages/ directory and execute it directly through the generated file path.

EPSS

Процентиль: 16%
0.00052
Низкий

8.8 High

CVSS3

Дефекты

CWE-434