CVE Feed

    Dashboard / CVE / CVE-2023-50982

    CVE-2023-50982

    Stud.IP 5.x through 5.3.3 allows XSS with resultant upload of executable files, because upload_action and edit_action in Admin_SmileysController do not check the file extension. This leads to remote code execution with the privileges of the www-data user. The fixed versions are 5.3.4, 5.2.6, 5.1.7, and 5.0.9.

    Published:Jan 8, 2024
    Last Modified:Jun 3, 2025
    EPS:Jan 8, 2024
    EPSS Score:0.00513
    CVSS Score:9

    Affected Products

    Vendor
    Studip
    Product
    Stud.ip

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High