CVE-2023-43838

HIGH

Personal Management System <1.4.64 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-43838. PoCs published by rootd4ddy.

AI-analyzed exploit summary This repository provides a functional proof-of-concept for CVE-2023-43838, demonstrating an arbitrary file upload vulnerability in Personal Management System v1.4.64. The exploit involves uploading a crafted SVG file containing JavaScript, which executes when the avatar is viewed.

Description

An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar.

Exploits (1)

nomisec WORKING POC 1 stars
by rootd4ddy · poc
https://github.com/rootd4ddy/CVE-2023-43838

This repository provides a functional proof-of-concept for CVE-2023-43838, demonstrating an arbitrary file upload vulnerability in Personal Management System v1.4.64. The exploit involves uploading a crafted SVG file containing JavaScript, which executes when the avatar is viewed.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Personal Management System v1.4.64
Auth required
Prerequisites: Access to upload an avatar in the Personal Management System · Ability to host the crafted SVG file on a webserver
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 7.8
EPSS 0.0058
EPSS Percentile 43.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
personal-management-system/personal_management_system 1.4.64
Published Oct 04, 2023
Tracked Since Feb 18, 2026