Security Advisory

CVE-2023-53889

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-15 20:28:23
Last updated 2026-05-12 20:46:34
Assigner VulnCheck
State PUBLISHED

Description

Perch CMS 3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload arbitrary PHP files through the assets management interface. Attackers can upload a malicious .phar file with embedded system command execution capabilities to execute arbitrary commands on the server.