CVE-2023-2453

Local file Inclusion (LFI) in Forum Infusion via Directory Traversal

There is insufficient sanitization of tainted file names that are directly concatenated with a path that is subsequently passed to a ‘require_once’ statement. This allows arbitrary files with the ‘.php’ extension for which the absolute path is known to be included and executed. There are no known means in PHPFusion through which an attacker can upload and target a ‘.php’ file payload.


We have discovered 171 live websites that are affected by CVE-2023-2453.

Run a Free Instant Scan




Affected Software

Product  PHPFusion
Category Content Management System
Vulnerable Domains171 live websites (96% of PHPFusion install base)
Vulnerable Versions
  • from 0 through 9.10.30
Vulnerable Versions Count19 versions ( 95% of all versions)


Common Weakness Enumeration

CWE-829 Inclusion of Functionality from Untrusted Control Sphere



Details

  • Published - Sep 5, 2023
  • Updated - Sep 27, 2024

Credits

  • Matthew Hogg (finder)

Website Distribution by Country

Number of websites using CVE-2023-2453
United States31 websites



Germany24 websites
Poland24 websites
GB19 websites
Netherlands16 websites
Hungary11 websites
Denmark8 websites
Czech Republic6 websites
Sweden4 websites
Slovakia4 websites

Website Distribution by TLD

Number of websites using CVE-2023-2453
.com32 websites
.pl18 websites
.de15 websites
.org13 websites
.eu13 websites
.nl10 websites
.net8 websites
.dk8 websites
.co.uk7 websites
.cz5 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-2453

Top websites that are affected by CVE-2023-2453. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.**.uk United States**,***
*********.com United States***,***
*******.de Germany*,***,***
*****.nu Sweden*,***,***
*********.cz Czech Republic*,***,***
*******.****.org Netherlands*,***,***
***************.pl Poland*,***,***
*********.org United States*,***,***
*******.***.la Laos*,***,***
**********.**.uk GB*,***,***
See full domain list

FAQ

CVE-2023-2453 is Inclusion of Functionality from Untrusted Control Sphere in PHPFusion
A total of 171 websites have been identified as vulnerable to CVE-2023-2453, based on global website indexing conducted by WebTechSurvey.
The PHPFusion is affected by the CVE-2023-2453 vulnerability.
PHPFusion versions up to and including 9.10.30 are vulnerable to CVE-2023-2453.