VYPR
Unrated severityNVD Advisory· Published Dec 15, 2025· Updated Apr 7, 2026

Zomplog 3.9 Remote Code Execution via Authenticated File Manipulation

CVE-2023-53888

Description

Zomplog 3.9 contains a remote code execution vulnerability that allows authenticated attackers to inject and execute arbitrary PHP code through file manipulation endpoints. Attackers can upload malicious JavaScript files, rename them to PHP, and execute system commands by exploiting the saveE and rename actions in the application.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.