PT-2025-51286 · Unknown · Coppermine-Gallery

Mirabbas Ağalarov

·

Published

2025-12-15

·

Updated

2025-12-21

·

CVE-2023-53868

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Coppermine Gallery version 1.6.25
Description Coppermine Gallery version 1.6.25 has a remote code execution issue. Authenticated attackers can upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file containing system commands to the plugin directory and then execute arbitrary code by accessing the uploaded plugin script. The vulnerability affects systems where an authenticated user has the ability to manage plugins.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the plugin manager functionality to prevent unauthorized file uploads.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-53868

Affected Products

Coppermine-Gallery