Remote Code Execution Vulnerability in WBCE CMS by WBCE Developers
CVE-2024-58283
Key Information:
Badges
What is CVE-2024-58283?
WBCE CMS version 1.6.2 is susceptible to a remote code execution vulnerability that enables authenticated attackers to exploit the Elfinder file manager. By leveraging the file upload functionality within the Elfinder connector, attackers can upload malicious PHP files, effectively gaining the ability to execute arbitrary commands on the server. This vulnerability poses significant risks, allowing for unauthorized access and control over the affected system.
Affected Version(s)
WBCE CMS 1.6.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
