CVE-2023-53889

Publication date

2025-12-15 20:28:23

Family

VulnCheck

State

PUBLISHED

Description

Perch CMS 3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload arbitrary PHP files through the assets management interface. Attackers can upload a malicious .phar file with embedded system command execution capabilities to execute arbitrary commands on the server.