CVE-2023-53921
CRITICALSitemagicCMS 4.4.3 - PHP File Upload Command Execution
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2023-53921. PoCs published by Mirabbas Ağalarov.
AI-analyzed exploit summary This exploit demonstrates a file upload vulnerability in SitemagicCMS 4.4.3, allowing remote code execution by uploading a malicious .phar file containing PHP code. The PoC includes a multipart/form-data request to bypass restrictions and execute arbitrary commands.
Description
SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. Attackers can upload a .phar file with system command execution payload to compromise the web application and execute arbitrary system commands.
Exploits (1)
This exploit demonstrates a file upload vulnerability in SitemagicCMS 4.4.3, allowing remote code execution by uploading a malicious .phar file containing PHP code. The PoC includes a multipart/form-data request to bypass restrictions and execute arbitrary commands.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H