Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6cfr-35cv-65w6

Опубликовано: 15 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 7.2

Описание

Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject system commands through PHP page creation. Attackers can create a new PHP page with malicious system commands in the description field to execute arbitrary commands on the server.

Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject system commands through PHP page creation. Attackers can create a new PHP page with malicious system commands in the description field to execute arbitrary commands on the server.

EPSS

Процентиль: 60%
0.00396
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.2
nvd
около 2 месяцев назад

Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject system commands through PHP page creation. Attackers can create a new PHP page with malicious system commands in the description field to execute arbitrary commands on the server.

EPSS

Процентиль: 60%
0.00396
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-94