Record summary

CVE-2023-53950 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.

Description

InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file extension restrictions through filename manipulation. Attackers can upload malicious ASP shells by using null byte techniques and alternate file extensions to circumvent upload controls in the asset manager.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 19, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListThrough 5.4affected

Proofs of concept

1

Catalogued exploits

ExploitDBInnovaStudio WYSIWYG Editor 5.4 - Unrestricted File Upload / Directory TraversalExploitDB exploitby Zer0FauLTNot analyzed1 file
ExploitDB

PoC details

References

4