CVE-2025-23953

CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Scriptonite user files user-files allows Upload a Web Shell to a Web Server.This issue affects user files: from n/a through <= 2.4.2.

Affects 0 products across 2 vendors.

BCS7.03
CVSS 3.110.0
EPSS0.6%
Percentile48th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-434: Unrestricted Upload of File with Dangerous Type

Application allows file uploads without validating type, enabling upload of executable code or web shells.

Related Attack Patterns (CAPEC)
CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs
via CWE-434

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in Scriptonite versions up to 2.4.2 allows for the unrestricted upload of files with dangerous types, specifically web shells, which can lead to remote code execution and full server compromise.

BSID: BS-2025-GLOBAL-043571-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-23953?
A critical vulnerability in Scriptonite versions up to 2.4.2 allows for the unrestricted upload of files with dangerous types, specifically web shells, which can lead to remote code execution and full server compromise.
What is the CVSS score for CVE-2025-23953?
CVE-2025-23953 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 0.6%.
Is CVE-2025-23953 actively exploited?
No confirmed active exploitation of CVE-2025-23953 as of 2026-05-30.
How do I remediate CVE-2025-23953?
Priority: IMMEDIATE.
What systems are affected by CVE-2025-23953?
CVE-2025-23953 affects: Files, Scriptonite.
Vulnerability Details
CVE IDCVE-2025-23953
BSIDBS-2025-GLOBAL-043571-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2025-01-22
Last Modified2026-04-23
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

Unrestricted Upload of File with Dangerous Type vulnerability in Scriptonite user files user-files allows Upload a Web Shell to a Web Server.This issue affects user files: from n/a through <= 2.4.2.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit this vulnerability by uploading a malicious web shell file to the user-files directory. Once uploaded, the attacker can access the web shell to execute arbitrary commands on the server, potentially leading to unauthorized access, data theft, or further system compromise.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Files &mdash;
Scriptonite &mdash;
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 556 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash52b3c80f508a6ece398513ffc6f84e317b38d699034befe659c414895db85597c7c6e74b1305d752c3197c4b7241312c29920215e7847855e497cb7c15880149
Related CVEs affecting Files
CVE-2025-12539 10.0 The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensit... CVE-1999-0498 10.0 TFTP is not running in a restricted directory, allowing a remote attacker to ... CVE-2025-32510 10.0 Unrestricted Upload of File with Dangerous Type vulnerability in ovatheme Ova... CVE-1999-0561 10.0 IIS has the #exec function enabled for Server Side Include (SSI) files. CVE-2025-48148 10.0 Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper ...
View all Files CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →