CVE-2023-53902: WebsiteBaker 2.13.3 Directory Traversal via Media Delete Endpoint
WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary files by manipulating directory path parameters. Attackers can send crafted GET requests to /admin/media/delete.php with directory traversal sequences to delete files outside the intended directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-53902?
CVE-2023-53902 is categorized as a high-severity vulnerability due to its potential for arbitrary file deletion by authenticated attackers.
How do I fix CVE-2023-53902?
To mitigate CVE-2023-53902, update WebsiteBaker to the latest version where this vulnerability is patched.
What type of vulnerability is CVE-2023-53902?
CVE-2023-53902 is a directory traversal vulnerability that allows attackers to manipulate file paths to delete files.
Who is affected by CVE-2023-53902?
CVE-2023-53902 affects users of WebsiteBaker version 2.13.3.
What can attackers do with CVE-2023-53902?
Attackers can exploit CVE-2023-53902 to send crafted GET requests and delete arbitrary files on the server.