TROYANOSYVIRUS
Back to CVEs

CVE-2023-53894

CRITICAL
9.8

Description

phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP files to the server.

CVE Details

CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published12/16/2025
Last Modified1/21/2026
Sourcenvd
Honeypot Sightings0

Affected Products

dulldusk:phpfilemanager

Weaknesses (CWE)

CWE-1390

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.