Arbitrary Code Execution Vulnerability in ProcessWire CMS
CVE-2023-24676

7.2HIGH

Key Information:

Vendor
CVE Published:
24 January 2024

What is CVE-2023-24676?

A security concern exists in ProcessWire version 3.0.210 that can allow attackers to execute arbitrary code by utilizing the download_zip_url parameter when a new module is installed. Although the potential for exploitation is debated, it is notable that an administrator within ProcessWire has the capability to initiate the installation of any module, including those containing malicious or arbitrary code. This vulnerability emphasizes the importance of stringent access controls and cautious module management within ProcessWire installations.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.