PT-2025-52320 · Unknown · Easyphp Webserver

Rafael Pedrero

·

Published

2025-12-18

·

Updated

2025-12-26

·

CVE-2023-53941

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EasyPHP Webserver version 14.1
Description An unauthenticated attacker can execute arbitrary system commands. This is possible by injecting malicious payloads through the app service control parameter. Attackers can send POST requests to the ''/index.php?zone=settings'' endpoint with crafted app service control values to execute commands with administrative privileges.
Recommendations Upgrade EasyPHP Webserver version 14.1 to address this issue.

Exploit

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-53941

Affected Products

Easyphp Webserver