Vulnerability Description
WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary files by manipulating directory path parameters. Attackers can send crafted GET requests to /admin/media/delete.php with directory traversal sequences to delete files outside the intended directory.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Websitebaker | Websitebaker | 2.13.3 |
Related Weaknesses (CWE)
References
- https://websitebaker.org/pages/en/home.phpProduct
- https://www.exploit-db.com/exploits/51554ExploitThird Party AdvisoryVDB Entry
- https://www.vulncheck.com/advisories/websitebaker-directory-traversal-via-media-Third Party AdvisoryExploit
FAQ
What is CVE-2023-53902?
CVE-2023-53902 is a vulnerability with a CVSS score of 6.5 (MEDIUM). WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary files by manipulating directory path parameters. Attackers can send crafted GET...
How severe is CVE-2023-53902?
CVE-2023-53902 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-53902?
Check the references section above for vendor advisories and patch information. Affected products include: Websitebaker Websitebaker.