Official Product Homepageproduct
http://flatnux.altervista.org/flatnux.html CVE-2023-53956
HIGH
Flatnux 2021-03.25 Authenticated File Upload Remote Code Execution
Record summary
CVE-2023-53956 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
Flatnux 2021-03.25 contains an authenticated file upload vulnerability that allows administrative users to upload arbitrary PHP files through the file manager. Attackers with admin credentials can upload malicious PHP scripts to the web root directory, enabling remote code execution on the server.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 19, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
flatnuxBrowse altervista / flatnux | CVE List | 2021-03.25 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBflatnux 2021-03.25 - Remote Code Execution (Authenticated)ExploitDB exploitby Ömer Hasan DurmuşNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-53956 ExploitDB-51295exploit
https://www.exploit-db.com/exploits/51295 VulnCheck Advisory: Flatnux 2021-03.25 Authenticated File Upload Remote Code ExecutionThird-party advisory
https://www.vulncheck.com/advisories/flatnux-authenticated-file-upload-remote-code-execution