TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload malicious PHP files. Attackers can upload .phar files with embedded system commands to execute arbitrary code on the server by accessing the uploaded file's URL.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Dec 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tinywebgallery
Tinywebgallery tinywebgallery |
|
| Vendors & Products |
Tinywebgallery
Tinywebgallery tinywebgallery |
Wed, 17 Dec 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload malicious PHP files. Attackers can upload .phar files with embedded system commands to execute arbitrary code on the server by accessing the uploaded file's URL. | |
| Title | TinyWebGallery v2.5 Remote Code Execution via Unrestricted File Upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-17T22:44:53.801Z
Reserved: 2025-12-16T19:22:09.995Z
Link: CVE-2023-53922
No data.
Status : Received
Published: 2025-12-17T23:15:51.270
Modified: 2025-12-17T23:15:51.270
Link: CVE-2023-53922
No data.
OpenCVE Enrichment
Updated: 2025-12-18T09:56:21Z