vendor:
Webutler CMS
by:
Mirabbas Agalarov
7.5
CVSS
HIGH
Remote Code Execution (RCE)
94
CWE
Product Name: Webutler CMS
Affected Version From: v3.2
Affected Version To: v3.2
Patch Exists: NO
Related CWE:
CPE: webutler
Platforms Tested: Linux
2023
Webutler v3.2 – Remote Code Execution (RCE)
This exploit allows an attacker to execute arbitrary code remotely on a system running Webutler CMS v3.2. By uploading a specially crafted phar file, the attacker can trigger the execution of arbitrary PHP code, in this case, printing the contents of the /etc/passwd file. This vulnerability can be used to gain unauthorized access to sensitive information or further compromise the system.
Mitigation:
To mitigate this vulnerability, it is recommended to apply the latest patch or update to a version that addresses this issue. Additionally, restrict access to the affected system and ensure that only trusted users have administrative privileges.