Description
Stud.IP 5.x through 5.3.3 allows XSS with resultant upload of executable files, because upload_action and edit_action in Admin_SmileysController do not check the file extension. This leads to remote code execution with the privileges of the www-data user. The fixed versions are 5.3.4, 5.2.6, 5.1.7, and 5.0.9.
References (3)
Core 3
Core References
Exploit, Third Party Advisory
https://rehmeinfosec.de/labor/cve-2023-50982
Scores
CVSS v3
9.0
EPSS
0.0051
EPSS Percentile
66.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-434
CWE-79
Status
published
Products (1)
studip/stud.ip
< 5.0.9
Published
Jan 08, 2024
Tracked Since
Feb 18, 2026