PT-2025-51287 · Unknown · Webigniter
Nu11Secur1Ty
·
Published
2025-12-15
·
Updated
2025-12-21
·
CVE-2023-53869
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
WEBIGniter version 28.7.23
Description
The software contains a file upload issue that permits authenticated attackers to upload and execute malicious PHP files via the media function. An attacker with any valid account can upload PHP scripts, leading to remote code execution on the application server.
Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict file upload functionality to trusted users only.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webigniter