CVE-2023-53941

CRITICAL

CVSS v3

9.8

CRITICAL

EPSS Score

68.6%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by injecting malicious payloads through the app_service_control parameter. Attackers can send POST requests to /index.php?zone=settings with crafted app_service_control values to execute commands with administrative privileges.

Technical Details

CVSS v3 Vector
3.1
Published
12/18/2025
Last Modified
12/26/2025

Frequently Asked Questions

What is CVE-2023-53941?

EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by injecting malicious payloads through the app_service_control parameter. Attackers can send POST requests to /index.php?zone=settings with crafted app_service_control values to execute commands with administrative privileges.

Is CVE-2023-53941 actively exploited?

Active exploitation of CVE-2023-53941 has not been confirmed. The EPSS score is 68.6%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-53941?

CVE-2023-53941 has a CVSS v3 base score of 9.8 (CRITICAL severity), with vector string 3.1.

Is CVE-2023-53941 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.