Unrated severityNVD Advisory· Published Dec 15, 2025· Updated Apr 7, 2026
Zomplog 3.9 Remote Code Execution via Authenticated File Manipulation
CVE-2023-53888
Description
Zomplog 3.9 contains a remote code execution vulnerability that allows authenticated attackers to inject and execute arbitrary PHP code through file manipulation endpoints. Attackers can upload malicious JavaScript files, rename them to PHP, and execute system commands by exploiting the saveE and rename actions in the application.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/51624mitreexploit
- www.vulncheck.com/advisories/zomplog-remote-code-execution-via-authenticated-file-manipulationmitrethird-party-advisory
- web.archive.org/web/20080616153330/http://zomp.nl/zomplog/mitreproduct
News mentions
0No linked articles in our index yet.