First published: Wed Jan 22 2025(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in Innovative Solutions user files allows Upload a Web Shell to a Web Server. This issue affects user files: from n/a through 2.4.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Innovative Solutions user files | >=n/a<2.4.2 | |
WordPress user files plugin | <=2.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23953 has a high severity rating due to its potential for allowing attackers to upload malicious web shells.
To fix CVE-2025-23953, update your Innovative Solutions user files or WordPress user files plugin to a version higher than 2.4.2.
CVE-2025-23953 affects the Innovative Solutions user files and WordPress user files plugin versions up to 2.4.2.
Attackers can exploit CVE-2025-23953 to upload web shells to the server, potentially gaining unauthorized access to the system.
CVE-2025-23953 was officially published in the CVE database as part of the ongoing effort to track vulnerabilities in software.