CVE-2023-53971
HIGHWebTareas 2.4 - Authenticated Remote Code Execution via Chat Photo Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-53971. PoCs published by Hubert Wojciechowski.
AI-analyzed exploit summary This exploit demonstrates an authenticated file upload vulnerability in WebTareas 2.4, allowing an attacker to upload a malicious PHP file disguised as an image (snupi.php) via the chatPhotos0 parameter. The uploaded file is then accessible at /files/Messages/7.php, leading to remote code execution (RCE).
Description
WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functionality. Attackers can upload a PHP file with arbitrary code to the /files/Messages/ directory and execute it directly through the generated file path.
Exploits (1)
This exploit demonstrates an authenticated file upload vulnerability in WebTareas 2.4, allowing an attacker to upload a malicious PHP file disguised as an image (snupi.php) via the chatPhotos0 parameter. The uploaded file is then accessible at /files/Messages/7.php, leading to remote code execution (RCE).
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H