InnovaStudio WYSIWYG Editor 5.4 Unrestricted File Upload via Filename Manipulation
Vulnerability Description
InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file extension restrictions through filename manipulation. Attackers can upload malicious ASP shells by using null byte techniques and alternate file extensions to circumvent upload controls in the asset manager.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-53950
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Zer0FauLT
Affected Vendor
innovastudio
View all reports →