WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary files by manipulating directory path parameters. Attackers can send crafted GET requests to /admin/media/delete.php with directory traversal sequences to delete files outside the intended directory.
Metrics
Affected Vendors & Products
References
History
Tue, 16 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Websitebaker
Websitebaker websitebaker |
|
| Vendors & Products |
Websitebaker
Websitebaker websitebaker |
Tue, 16 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 16 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary files by manipulating directory path parameters. Attackers can send crafted GET requests to /admin/media/delete.php with directory traversal sequences to delete files outside the intended directory. | |
| Title | WebsiteBaker 2.13.3 Directory Traversal via Media Delete Endpoint | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-16T17:03:48.466Z
Updated: 2025-12-16T21:43:30.387Z
Reserved: 2025-12-16T00:10:40.314Z
Link: CVE-2023-53902
Updated: 2025-12-16T21:43:27.576Z
Status : Received
Published: 2025-12-16T17:16:02.537
Modified: 2025-12-16T18:16:07.350
Link: CVE-2023-53902
No data.