Medium severity6.5NVD Advisory· Published Dec 16, 2025· Updated Jun 17, 2026
CVE-2023-53902
CVE-2023-53902
Description
WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary files by manipulating directory path parameters. Attackers can send crafted GET requests to /admin/media/delete.php with directory traversal sequences to delete files outside the intended directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:websitebaker:websitebaker:2.13.3:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:websitebaker:websitebaker:2.13.3:*:*:*:*:*:*:*
- (no CPE)range: =2.13.3
- (no CPE)range: 2.13.3
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/51554nvdExploitThird Party AdvisoryVDB Entry
- www.vulncheck.com/advisories/websitebaker-directory-traversal-via-media-delete-endpointnvdExploitThird Party Advisory
- websitebaker.org/pages/en/home.phpnvdProduct
News mentions
0No linked articles in our index yet.