WEBIGniter 28.7.23 contains a file upload vulnerability that allows authenticated attackers to upload and execute dangerous PHP files through the media function. Attackers can leverage any created account to upload malicious PHP scripts that enable remote code execution on the application server.
Metrics
Affected Vendors & Products
References
History
Tue, 16 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webigniter
Webigniter webigniter |
|
| Vendors & Products |
Webigniter
Webigniter webigniter |
Mon, 15 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WEBIGniter 28.7.23 contains a file upload vulnerability that allows authenticated attackers to upload and execute dangerous PHP files through the media function. Attackers can leverage any created account to upload malicious PHP scripts that enable remote code execution on the application server. | |
| Title | WEBIGniter 28.7.23 Unrestricted File Upload Remote Code Execution | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-15T20:28:13.705Z
Updated: 2025-12-15T21:48:29.132Z
Reserved: 2025-12-13T14:25:04.998Z
Link: CVE-2023-53869
Updated: 2025-12-15T21:41:42.781Z
Status : Awaiting Analysis
Published: 2025-12-15T21:15:49.263
Modified: 2025-12-16T14:10:11.300
Link: CVE-2023-53869
No data.