← Vulnerability feed

Vulnerability record · CVE-2023-38836 · published 21 August 2023

CVE-2023-38836: BoidCMS unrestricted file upload enables remote code execution

BBoidcms · Boidcms

BoidCMS 2.0.0 fails to properly validate uploaded files, allowing an attacker to prepend a GIF header to a malicious file and bypass MIME type checks. Because the uploaded file can be executed, this turns a routine upload feature into a remote code execution path. The flaw is tracked as CWE-434 and rated CVSS 3.1 8.8 (High).

8.8 CVSS 3.1 High EPSS 76% · top 0.5% CWE-434 · Unrestricted file upload
8.8CVSS 3.1 base score
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
9 Jul 2026Last modified by NVD

Description

File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 8.8 with a very high EPSS score and public exploit references make this a high-priority remote code execution risk, though it requires low-privilege authenticated access and is not in KEV.

What it is

BoidCMS 2.0.0 fails to properly validate uploaded files, allowing an attacker to prepend a GIF header to a malicious file and bypass MIME type checks. Because the uploaded file can be executed, this turns a routine upload feature into a remote code execution path. The flaw is tracked as CWE-434 and rated CVSS 3.1 8.8 (High).

Impact

An attacker who can reach the upload function can place and execute arbitrary code on the server, leading to full compromise of the web application and its host. Confidentiality, integrity and availability impacts are all rated High.

Attack surface

The vulnerability is network-reachable (AV:N) with low attack complexity and no user interaction, but the CVSS vector requires low privileges (PR:L), so the attacker needs some authenticated access to the upload functionality. No affected version beyond 2.0.0 is stated in the record.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high at 0.7603 (99.5th percentile) and public references are tagged Exploit, including a Packet Storm shell upload write-up and the vendor issue tracker. This indicates public exploit code and active interest, though no confirmed in-the-wild campaign is documented in the record.

What to do

  • Upgrade BoidCMS to a version later than 2.0.0 if one is available; the record does not name a fixed version, so confirm with the vendor.
  • Restrict or disable file upload functionality for untrusted or low-privilege accounts.
  • Validate uploads by content and extension on the server side, not by client-supplied MIME type or magic bytes alone.
  • Store uploaded files outside the web root and serve them without execute permissions.
  • Run the CMS under a least-privilege account and apply WAF rules blocking executable file uploads.

Detection

  • Monitor web server and application logs for uploads of files with executable extensions or GIF-prefixed payloads.
  • Alert on new files written to web-accessible directories, especially those with .php, .phtml, .jsp or similar extensions.
  • Watch for outbound connections or child processes spawned by the web server user, which can indicate uploaded shell execution.
  • Correlate upload events with subsequent requests to the uploaded file path from the same source.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-38836 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2026-39387Boidcms php remote file inclusion vulnerabilityBoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. Versions prior to 2.1.3 are vu…EPSS 0.81%6.1CVE-2024-32342Boidcms cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in the Create Page of Boid CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a craf…EPSS 0.43%6.1CVE-2024-32343Boidcms cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in the Create Page of Boid CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a craf…EPSS 0.41%5.4CVE-2023-48824Boidcms cross-site scripting vulnerabilityBoidCMS 2.0.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the title, subtitle, footer, or keywords parameter in a page=cre…EPSS 0.46%5.3CVE-2024-53255Boidcms cross-site scripting vulnerabilityBoidCMS is a free and open-source flat file CMS for building simple websites and blogs, developed using PHP and uses JSON as a database. In affected …EPSS 0.89%10.0CVE-2026-56291Balbooa Forms Joomla extension unauthenticated arbitrary file upload RCEThe Balbooa Forms extension for Joomla before version 2.4.1 accepts file uploads without authentication and does not restrict file type, allowing exe…KEVEPSS 15%analysed10.0CVE-2026-48939iCagenda Joomla extension unrestricted file upload leads to PHP RCEThe iCagenda extension for Joomla fails to restrict file types in its file attachment feature, allowing arbitrary file uploads that result in PHP cod…KEVEPSS 20%analysed10.0CVE-2026-56290Joomla Page Builder CK unauthenticated file upload leads to RCEThe Joomla Page Builder CK extension before 3.6.0 allows unauthenticated arbitrary file uploads, letting an attacker place executable files on the se…KEVEPSS 31%analysed

Source: NIST National Vulnerability Database (record CVE-2023-38836), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.