CVE-2023-50982: Studip Stud.ip

Critical severity, CVSS 9.0. EPSS: 1.3% chance of exploitation in the next 30 days.

Stud.IP 5.x through 5.3.3 allows XSS with resultant upload of executable files, because upload_action and edit_action in Admin_SmileysController do not check the file extension. This leads to remote code execution with the privileges of the www-data user. The fixed versions are 5.3.4, 5.2.6, 5.1.7, and 5.0.9.

Affected products

  • Studip Stud.ip: before 5.0.9 (fixed in 5.0.9); from 5.1, before 5.1.7 (fixed in 5.1.7); from 5.2, before 5.2.6 (fixed in 5.2.6); from 5.3, before 5.3.4 (fixed in 5.3.4)

Published 2024-01-08. Last modified 2026-06-17.