CVE-2023-53868
Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory and execute arbitrary code by accessing the uploaded plugin script.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://web.archive.org/web/20240101151648/https://coppermine-gallery.net/, https://www.exploit-db.com/exploits/51738, https://www.vulncheck.com/advisories/coppermine-gallery-remote-code-execution-via-plugin-upload
