CVE-2023-37152

CRITICAL

Online Art Gallery - Unrestricted File Upload

Title source: rule

Description

Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Ramil Mustafayev · pythonwebappsphp
https://www.exploit-db.com/exploits/51524

Scores

CVSS v3 9.8
EPSS 0.0113
EPSS Percentile 78.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
online_art_gallery_project/online_art_gallery 1.0
Published Jul 10, 2023
Tracked Since Feb 18, 2026