CVE-2023-53902
Severity CVSS v4.0:
HIGH
Type:
CWE-22
Path Traversal
Publication date:
16/12/2025
Last modified:
24/12/2025
Description
WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary files by manipulating directory path parameters. Attackers can send crafted GET requests to /admin/media/delete.php with directory traversal sequences to delete files outside the intended directory.
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:websitebaker:websitebaker:2.13.3:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



