VulnerabilityAnalyzed
CVE-2023-53871
Soosyze 2.0.0 contains a file upload vulnerability that allows attackers to upload arbitrary HTML files with embedded PHP code to the application.
MEDIUM 6.9EPSS 0.64%
Does this matter?
Lower severity and a low EPSS score (0.64%). Track it; it rarely justifies an emergency change on its own.
Description
Soosyze 2.0.0 contains a file upload vulnerability that allows attackers to upload arbitrary HTML files with embedded PHP code to the application. Attackers can exploit the broken file upload mechanism to potentially view sensitive file paths and execute malicious PHP scripts on the server.
- CVSS 4.0
- 6.9 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.64% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- soosyze/soosyze
- Source
- disclosure@vulncheck.com
References
- https://github.com/soosyze/soosyzeProduct
- https://soosyze.com/Product
- https://www.exploit-db.com/exploits/51718Exploit, Third Party Advisory, VDB Entry
- https://www.vulncheck.com/advisories/soosyze-unrestricted-file-upload-via-broken-upload-logicThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.