vendor:
Webedition CMS
by:
Mirabbas Agalarov
7.5
CVSS
HIGH
Remote Code Execution (RCE)
CWE
Product Name: Webedition CMS
Affected Version From: v2.9.8.8
Affected Version To: v2.9.8.8
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
2023
Webedition CMS v2.9.8.8 – Remote Code Execution (RCE)
This exploit allows an attacker to execute arbitrary code on a remote system running Webedition CMS v2.9.8.8. By injecting malicious PHP code into the Description area of a new Webedition page, an attacker can execute system commands, such as reading sensitive files like /etc/passwd. The exploit requires the attacker to have login credentials.
Mitigation:
Update to a patched version of Webedition CMS that addresses the vulnerability. Implement strong access controls to limit the privileges of user accounts.