CVE-2023-53868: Coppermine Gallery 1.6.25 Remote Code Execution via Plugin Upload
Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory and execute arbitrary code by accessing the uploaded plugin script.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-53868?
CVE-2023-53868 has a critical severity rating due to its potential for remote code execution.
How do I fix CVE-2023-53868?
To fix CVE-2023-53868, update Coppermine Gallery to the latest version that addresses this vulnerability.
Who is affected by CVE-2023-53868?
Authenticated users of Coppermine Gallery version 1.6.25 are affected by CVE-2023-53868.
What type of vulnerability is CVE-2023-53868?
CVE-2023-53868 is a remote code execution vulnerability that allows attackers to execute arbitrary code.
How can attackers exploit CVE-2023-53868?
Attackers can exploit CVE-2023-53868 by uploading malicious PHP files through the plugin manager of the affected version.