Vulnerability record · CVE-2023-38836 · published 21 August 2023
CVE-2023-38836: BoidCMS unrestricted file upload enables remote code execution
BBoidcms · Boidcms
BoidCMS 2.0.0 fails to properly validate uploaded files, allowing an attacker to prepend a GIF header to a malicious file and bypass MIME type checks. Because the uploaded file can be executed, this turns a routine upload feature into a remote code execution path. The flaw is tracked as CWE-434 and rated CVSS 3.1 8.8 (High).
Description
File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with a very high EPSS score and public exploit references make this a high-priority remote code execution risk, though it requires low-privilege authenticated access and is not in KEV.
What it is
BoidCMS 2.0.0 fails to properly validate uploaded files, allowing an attacker to prepend a GIF header to a malicious file and bypass MIME type checks. Because the uploaded file can be executed, this turns a routine upload feature into a remote code execution path. The flaw is tracked as CWE-434 and rated CVSS 3.1 8.8 (High).
Impact
An attacker who can reach the upload function can place and execute arbitrary code on the server, leading to full compromise of the web application and its host. Confidentiality, integrity and availability impacts are all rated High.
Attack surface
The vulnerability is network-reachable (AV:N) with low attack complexity and no user interaction, but the CVSS vector requires low privileges (PR:L), so the attacker needs some authenticated access to the upload functionality. No affected version beyond 2.0.0 is stated in the record.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high at 0.7603 (99.5th percentile) and public references are tagged Exploit, including a Packet Storm shell upload write-up and the vendor issue tracker. This indicates public exploit code and active interest, though no confirmed in-the-wild campaign is documented in the record.
What to do
- Upgrade BoidCMS to a version later than 2.0.0 if one is available; the record does not name a fixed version, so confirm with the vendor.
- Restrict or disable file upload functionality for untrusted or low-privilege accounts.
- Validate uploads by content and extension on the server side, not by client-supplied MIME type or magic bytes alone.
- Store uploaded files outside the web root and serve them without execute permissions.
- Run the CMS under a least-privilege account and apply WAF rules blocking executable file uploads.
Detection
- Monitor web server and application logs for uploads of files with executable extensions or GIF-prefixed payloads.
- Alert on new files written to web-accessible directories, especially those with .php, .phtml, .jsp or similar extensions.
- Watch for outbound connections or child processes spawned by the web server user, which can indicate uploaded shell execution.
- Correlate upload events with subsequent requests to the uploaded file path from the same source.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/175026/BoidCMS-2.0.0-Shell-Upload.html | |
| https://github.com/BoidCMS/BoidCMS/issues/27 | ExploitIssue TrackingVendor Advisory |
| http://packetstormsecurity.com/files/175026/BoidCMS-2.0.0-Shell-Upload.html | |
| https://github.com/BoidCMS/BoidCMS/issues/27 | ExploitIssue TrackingVendor Advisory |
Track CVE-2023-38836 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-38836), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.