Threat Intel

v0.1

← CVEs

CVE-2023-53971

HIGH 8.8
Published
2025-12-22
Last Modified
2025-12-26
Affected Apps
15
Affected Devices
50
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functionality. Attackers can upload a PHP file with arbitrary code to the /files/Messages/ directory and execute it directly through the generated file path.
References 3