CVE-2023-38947
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published Aug 3, 2023
Updated: Aug 1, 2024
CWE ID 434
CWE ID 616
Summary
CVE-2023-38947 is a critical vulnerability affecting the WBCE CMS v1.6.1, specifically the /languages/install.php component. An attacker can exploit this arbitrary file upload vulnerability to upload a malicious PHP file, thereby gaining the ability to execute arbitrary code. This issue poses a serious risk, as it can lead to unauthorized system access and potential data breaches. It is strongly recommended that users of this CMS version upgrade to a patched version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share