Critical severity9.8NVD Advisory· Published Dec 19, 2025· Updated Apr 15, 2026
CVE-2023-53950
CVE-2023-53950
Description
InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file extension restrictions through filename manipulation. Attackers can upload malicious ASP shells by using null byte techniques and alternate file extensions to circumvent upload controls in the asset manager.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: = 5.4
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.