PT-2025-52521 · Innovastudio · Innovastudio Wysiwyg Editor

Zer0Fault

·

Published

2025-12-19

·

Updated

2025-12-20

·

CVE-2023-53950

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions InnovaStudio WYSIWYG Editor version 5.4
Description The software contains an unrestricted file upload issue that allows attackers to bypass file extension restrictions through filename manipulation. Attackers can upload malicious ASP shells by using null byte techniques and alternate file extensions to circumvent upload controls in the asset manager.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-53950

Affected Products

Innovastudio Wysiwyg Editor