CVE-2023-53944
EasyPHP Webserver 14.1 Path Traversal via Directory Traversal Sequences
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access files outside the document root by bypassing SecurityManager restrictions. Attackers can send GET requests with encoded directory traversal sequences like /..%5c..%5c to read system files such as /windows/win.ini.
| CWE | CWE-22 |
| Vendor | easyphp |
| Product | easyphp webserver |
| Published | Dec 18, 2025 |
| Last Updated | Apr 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for easyphp easyphp webserver
Be the first to know when new medium vulnerabilities affecting easyphp easyphp webserver are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Easyphp / EasyPHP Webserver
14.1
References
Credits
Rafael Pedrero