CVE-2023-53924

U

liCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to upload PHP files with .phar extension during profile avatar upload. Attackers can trigger code execution by visiting the uploaded file's location, enabling system command execution through maliciously crafted avatar uploads.

Configurations

Configuration 1 (hide)

cpe:2.3:a:ulicms:ulicms:2023.1:*:*:*:*:*:*:*

History

18 Dec 2025, 19:38

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-17 23:15

Updated : 2025-12-18 19:38


NVD link : CVE-2023-53924

Mitre link : CVE-2023-53924

CVE.ORG link : CVE-2023-53924


JSON object : View

Products Affected
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type