Vulnerability Description
Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files with system command payloads to the media upload endpoint and execute arbitrary commands on the server.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| S9Y | Serendipity | 2.4.0 |
Related Weaknesses (CWE)
References
- https://docs.s9y.org/Product
- https://www.exploit-db.com/exploits/51372ExploitThird Party AdvisoryVDB Entry
- https://www.vulncheck.com/advisories/serendipity-authenticated-remote-code-execuThird Party AdvisoryExploit
- https://www.exploit-db.com/exploits/51372ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2023-53933?
CVE-2023-53933 is a vulnerability with a CVSS score of 8.8 (HIGH). Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files with system command ...
How severe is CVE-2023-53933?
CVE-2023-53933 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-53933?
Check the references section above for vendor advisories and patch information. Affected products include: S9Y Serendipity.