Security Advisory

CVE-2023-53922

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-17 22:44:53
Last updated 2026-04-07 14:07:44
Assigner VulnCheck
State PUBLISHED

Description

TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload malicious PHP files. Attackers can upload .phar files with embedded system commands to execute arbitrary code on the server by accessing the uploaded files URL.