Critical severity9.8NVD Advisory· Published Apr 10, 2023· Updated Jun 17, 2026
CVE-2023-27178
CVE-2023-27178
Description
An arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary code via a crafted file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- GDidees/CMSdescription
=3.9.1+ 1 more
- (no CPE)range: =3.9.1
- cpe:2.3:a:gdidees:gdidees_cms:3.9.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- gist.github.com/Hadi999/4bc173bfb802c229b9bb397fa906847bnvdThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2022-40797nvdThird Party AdvisoryUS Government Resource
- salsa.debian.org/php-team/php/-/blob/dc253886b5b2e9bc8d9e36db787abb083a667fd8/debian/php-cgi.confnvdProduct
- www.gdidees.eu/cms-1-0.htmlnvdRelease Notes
News mentions
0No linked articles in our index yet.