VYPR
Medium severity5.4NVD Advisory· Published Dec 8, 2023· Updated Jun 17, 2026

CVE-2023-49444

CVE-2023-49444

Description

An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a crafted HTML or image file to the user avatar.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.