CVE-2023-53921

SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. Attackers can upload a .phar file with system command execution payload to compromise the web application and execute arbitrary system commands.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sitemagic:sitemagic_cms:4.4.3:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-17 23:15

Updated : 2025-12-31 18:36


NVD link : CVE-2023-53921

Mitre link : CVE-2023-53921

CVE.ORG link : CVE-2023-53921


JSON object : View

Products Affected

sitemagic

  • sitemagic_cms
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type