← back
CVE-2023-31689

CVE-2023-31689

CVSS 9.8 CRITICALEPSS 21.8%CWE-434
Vexday Risk Score
33Attention
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.8EPSS 21.8%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
22 May 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and the textAreaCode parameter. It can write arbitrary strings into custom file names and upload any files, and write malicious code to execute scripts to trigger command execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →