CVE-2023-31689
In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and the textAreaCode parameter.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 20.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and the textAreaCode parameter. It can write arbitrary strings into custom file names and upload any files, and write malicious code to execute scripts to trigger command execution.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 20.22% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- wcms/wcms
- Source
- cve@mitre.org
References
- https://github.com/vedees/wcms/issues/15Exploit, Issue Tracking
- https://github.com/vedees/wcms/issues/15Exploit, Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.