CVE-2023-53924

UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to upload PHP files with .phar extension during profile avatar upload. Attackers can trigger code execution by visiting the uploaded file's location, enabling system command execution through maliciously crafted avatar uploads.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ulicms:ulicms:2023.1:*:*:*:*:*:*:*

History

18 Dec 2025, 19:38

Type Values Removed Values Added
First Time Ulicms
Ulicms ulicms
References () https://web.archive.org/web/20230314183734/https://en.ulicms.de/ - () https://web.archive.org/web/20230314183734/https://en.ulicms.de/ - Product
References () https://www.exploit-db.com/exploits/51434 - () https://www.exploit-db.com/exploits/51434 - Exploit
References () https://www.vulncheck.com/advisories/ulicms-sniffing-vicuna-remote-code-execution-via-avatar-upload - () https://www.vulncheck.com/advisories/ulicms-sniffing-vicuna-remote-code-execution-via-avatar-upload - Third Party Advisory
CPE cpe:2.3:a:ulicms:ulicms:2023.1:*:*:*:*:*:*:*

18 Dec 2025, 19:16

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/51434 - () https://www.exploit-db.com/exploits/51434 -

17 Dec 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-17 23:15

Updated : 2025-12-18 19:38


NVD link : CVE-2023-53924

Mitre link : CVE-2023-53924

CVE.ORG link : CVE-2023-53924


JSON object : View

Products Affected

ulicms

  • ulicms
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type