VYPR
Unrated severityNVD Advisory· Published Dec 15, 2025· Updated Apr 7, 2026

Webutler v3.2 Remote Code Execution via Arbitrary File Upload

CVE-2023-53885

Description

Webutler v3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload PHP files with system command execution. Attackers can upload a PHAR file with embedded system commands to the media browser and execute arbitrary commands by accessing the uploaded file.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.