CVE-2023-31505: Schlix CMS

High severity, CVSS 7.2. EPSS: 1.2% chance of exploitation in the next 30 days.

An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrary code and obtain sensitive information via a crafted .phtml file.

Affected products

  • Schlix CMS: version 2.2.8-1 only

Published 2024-01-31. Last modified 2026-06-17.