vendor:
WBCE CMS
by:
Ahmet Ümit BAYRAM
8.1
CVSS
CRITICAL
Remote Code Execution (RCE)
94
CWE
Product Name: WBCE CMS
Affected Version From: 1.6.2002
Affected Version To: 1.6.2002
Patch Exists: NO
Related CWE: CVE-2024-XXXX (To be assigned)
CPE: a:wbce_cms:wbce_cms:1.6.2
Platforms Tested: MacOS
2024
WBCE CMS v1.6.2 – Remote Code Execution (RCE)
The WBCE CMS version 1.6.2 allows remote attackers to execute arbitrary code via a crafted request. By uploading a malicious file, an attacker can execute commands on the server remotely.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version as soon as it is available. Avoid uploading files from untrusted sources.