← Zuruck zu CVEs
CVE-2023-53922
CRITICAL9.8
Beschreibung
TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload malicious PHP files. Attackers can upload .phar files with embedded system commands to execute arbitrary code on the server by accessing the uploaded file's URL.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht12/17/2025
Zuletzt geandert12/24/2025
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
tinywebgallery:tinywebgallery
Schwachen (CWE)
CWE-434
Referenzen
http://www.tinywebgallery.com/(disclosure@vulncheck.com)
https://www.exploit-db.com/exploits/51443(disclosure@vulncheck.com)
https://www.vulncheck.com/advisories/tinywebgallery-remote-code-execution-via-unrestricted-file-upload(disclosure@vulncheck.com)
https://www.exploit-db.com/exploits/51443(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.