← voltar
CVE-2023-53871

Soosyze 2.0.0 Unrestricted File Upload via Broken Upload Logic

CVSS 6.9 MEDIUMEPSS 0.5%CWE-434
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 6.9EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
15 dez 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Soosyze 2.0.0 contains a file upload vulnerability that allows attackers to upload arbitrary HTML files with embedded PHP code to the application. Attackers can exploit the broken file upload mechanism to potentially view sensitive file paths and execute malicious PHP scripts on the server.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Produtos afetados
Soosyze · Soosyze