CVE-2023-53944

Severity CVSS v4.0:
HIGH
Type:
CWE-22 Path Traversal
Publication date:
18/12/2025
Last modified:
19/12/2025

Description

EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access files outside the document root by bypassing SecurityManager restrictions. Attackers can send GET requests with encoded directory traversal sequences like /..%5c..%5c to read system files such as /windows/win.ini.