← Vulnerability feed

Vulnerability record · CVE-2023-53971 · published 22 December 2025

CVE-2023-53971: Webtareas project webtareas unrestricted file upload vulnerability

WWebtareas Project · Webtareas

WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functionality. Attackers can upload a PHP file with arbitrary code to the /files/Messages/ directory and execute it directly through the generated file path.

8.7 CVSS 4.0 High EPSS 0.48% · top 61.3% CWE-434 · Unrestricted file upload
8.7CVSS 4.0 base score
0.48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functionality. Attackers can upload a PHP file with arbitrary code to the /files/Messages/ directory and execute it directly through the generated file path.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-53971 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-44290Webtareas project webtareas sql injection vulnerabilitywebTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.EPSS 3.7%9.8CVE-2022-44291Webtareas project webtareas sql injection vulnerabilitywebTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.EPSS 3.7%9.8CVE-2021-43481Webtareas project webtareas sql injection vulnerabilityAn SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.EPSS 5.6%9.3CVE-2023-53972Webtareas project webtareas sql injection vulnerabilityWebTareas 2.4 contains a SQL injection vulnerability in the webTareasSID cookie parameter that allows unauthenticated attackers to manipulate databas…EPSS 0.43%8.8CVE-2021-41916Webtareas project webtareas cross-site request forgery vulnerabilityA Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and earlier allows a remote attacker to create a new administrative profil…EPSS 0.82%8.8CVE-2021-41919Webtareas project webtareas unrestricted file upload vulnerabilitywebTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without restrictions. This is workin…EPSS 2.4%7.5CVE-2021-41920Webtareas project webtareas sql injection vulnerabilitywebTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/libr…EPSS 1.7%7.5CVE-2020-25733Webtareas project webtareas unrestricted file upload vulnerabilitywebTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2023-53971), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.