CVE-2023-31689
CVE-2023-31689
Vexday Risk Score
33Attention
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.8EPSS 21.8%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
22 May 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and the textAreaCode parameter. It can write arbitrary strings into custom file names and upload any files, and write malicious code to execute scripts to trigger command execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://github.com/vedees/wcms/issues/15