Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory and execute arbitrary code by accessing the uploaded plugin script.
History

Mon, 15 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 15 Dec 2025 20:30:00 +0000

Type Values Removed Values Added
Description Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory and execute arbitrary code by accessing the uploaded plugin script.
Title Coppermine Gallery 1.6.25 Remote Code Execution via Plugin Upload
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-15T20:22:36.778Z

Updated: 2025-12-15T21:48:36.164Z

Reserved: 2025-12-13T14:25:04.997Z

Link: CVE-2023-53868

cve-icon Vulnrichment

Updated: 2025-12-15T21:41:51.269Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-15T21:15:49.107

Modified: 2025-12-16T14:10:11.300

Link: CVE-2023-53868

cve-icon Redhat

No data.