Zomplog 3.9 contains a remote code execution vulnerability that allows authenticated attackers to inject and execute arbitrary PHP code through file manipulation endpoints. Attackers can upload malicious JavaScript files, rename them to PHP, and execute system commands by exploiting the saveE and rename actions in the application.
Metrics
Affected Vendors & Products
References
History
Wed, 24 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zomp
Zomp zomplog |
|
| CPEs | cpe:2.3:a:zomp:zomplog:3.9:*:*:*:*:*:*:* | |
| Vendors & Products |
Zomp
Zomp zomplog |
|
| Metrics |
cvssV3_1
|
Tue, 16 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zomplog
Zomplog zomplog |
|
| Vendors & Products |
Zomplog
Zomplog zomplog |
Mon, 15 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zomplog 3.9 contains a remote code execution vulnerability that allows authenticated attackers to inject and execute arbitrary PHP code through file manipulation endpoints. Attackers can upload malicious JavaScript files, rename them to PHP, and execute system commands by exploiting the saveE and rename actions in the application. | |
| Title | Zomplog 3.9 Remote Code Execution via Authenticated File Manipulation | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-15T20:28:22.684Z
Updated: 2025-12-15T21:46:37.310Z
Reserved: 2025-12-15T01:02:32.434Z
Link: CVE-2023-53888
Updated: 2025-12-15T21:37:44.284Z
Status : Analyzed
Published: 2025-12-15T21:15:51.973
Modified: 2025-12-24T18:11:46.850
Link: CVE-2023-53888
No data.