Arbitrary Code Execution Vulnerability in ProcessWire CMS
CVE-2023-24676
7.2HIGH
What is CVE-2023-24676?
A security concern exists in ProcessWire version 3.0.210 that can allow attackers to execute arbitrary code by utilizing the download_zip_url parameter when a new module is installed. Although the potential for exploitation is debated, it is notable that an administrator within ProcessWire has the capability to initiate the installation of any module, including those containing malicious or arbitrary code. This vulnerability emphasizes the importance of stringent access controls and cautious module management within ProcessWire installations.
