CVE detail
CVE-2023-2453 — CVE-2023-2453
Published 2023-09-05 · Modified 2026-06-17 · Vendor php-fusion · Product phpfusion · Source nvd
HIGH
severity
CVSS-derived band
0.0074
EPSS probability
exploitation probability, 30d
51.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
There is insufficient sanitization of tainted file names that are directly concatenated with a path that is subsequently passed to a ‘require_once’ statement. This allows arbitrary files with the ‘.php’ extension for which the absolute path is known to be included and executed. There are no known means in PHPFusion through which an attacker can upload and target a ‘.php’ file payload.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References