UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to upload PHP files with .phar extension during profile avatar upload. Attackers can trigger code execution by visiting the uploaded file's location, enabling system command execution through maliciously crafted avatar uploads.
References
| Link | Resource |
|---|---|
| https://web.archive.org/web/20230314183734/https://en.ulicms.de/ | Product |
| https://www.exploit-db.com/exploits/51434 | Exploit |
| https://www.vulncheck.com/advisories/ulicms-sniffing-vicuna-remote-code-execution-via-avatar-upload | Third Party Advisory |
| https://www.exploit-db.com/exploits/51434 | Exploit |
Configurations
History
18 Dec 2025, 19:38
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Ulicms
Ulicms ulicms |
|
| References | () https://web.archive.org/web/20230314183734/https://en.ulicms.de/ - Product | |
| References | () https://www.exploit-db.com/exploits/51434 - Exploit | |
| References | () https://www.vulncheck.com/advisories/ulicms-sniffing-vicuna-remote-code-execution-via-avatar-upload - Third Party Advisory | |
| CPE | cpe:2.3:a:ulicms:ulicms:2023.1:*:*:*:*:*:*:* |
18 Dec 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.exploit-db.com/exploits/51434 - |
17 Dec 2025, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-17 23:15
Updated : 2025-12-18 19:38
NVD link : CVE-2023-53924
Mitre link : CVE-2023-53924
CVE.ORG link : CVE-2023-53924
JSON object : View
Products Affected
ulicms
- ulicms
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
