Unrated severityNVD Advisory· Published Dec 17, 2025· Updated Apr 7, 2026
SitemagicCMS 4.4.3 Remote Code Execution via Unrestricted File Upload
CVE-2023-53921
Description
SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. Attackers can upload a .phar file with system command execution payload to compromise the web application and execute arbitrary system commands.
Affected products
2- Range: =4.4.3
- Sitemagic/SitemagicCMSv5Range: 4.4.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/51464mitreexploit
- www.vulncheck.com/advisories/sitemagiccms-remote-code-execution-via-unrestricted-file-uploadmitrethird-party-advisory
- sitemagic.org/Download.htmlmitreproduct
News mentions
0No linked articles in our index yet.