PT-2025-51306 · Zomplog · Zomplog

Mirabbas Ağalarov

·

Published

2025-12-15

·

Updated

2025-12-24

·

CVE-2023-53888

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zomplog version 3.9
Description An authenticated attacker can inject and execute arbitrary PHP code through file manipulation endpoints. This is achieved by uploading malicious JavaScript files, renaming them to PHP, and then executing system commands via the saveE and rename actions within the application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2023-53888

Affected Products

Zomplog