Unrated severityNVD Advisory· Published Dec 15, 2025· Updated Apr 7, 2026
Webutler v3.2 Remote Code Execution via Arbitrary File Upload
CVE-2023-53885
Description
Webutler v3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload PHP files with system command execution. Attackers can upload a PHAR file with embedded system commands to the media browser and execute arbitrary commands by accessing the uploaded file.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/51660mitreexploit
- www.vulncheck.com/advisories/webutler-v-remote-code-execution-via-arbitrary-file-uploadmitrethird-party-advisory
- webutler.de/enmitreproduct
News mentions
0No linked articles in our index yet.