CVE-2023-53933 - Serendipity 2.4.0 Authenticated Remote Code Execution via File Upload
CVE ID : CVE-2023-53933
Published : Dec. 17, 2025, 11:15 p.m. | 2 hours, 44 minutes ago
Description : Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files with system command payloads to the media upload endpoint and execute arbitrary commands on the server.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Dec. 17, 2025, 11:15 p.m. | 2 hours, 44 minutes ago
Description : Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files with system command payloads to the media upload endpoint and execute arbitrary commands on the server.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...