Количество 2
Количество 2
CVE-2023-24676
An issue found in ProcessWire 3.0.210 allows attackers to execute arbitrary code and install a reverse shell via the download_zip_url parameter when installing a new module. NOTE: this is disputed because exploitation requires that the attacker is able to enter requests as an admin; however, a ProcessWire admin is intentionally allowed to install any module that contains any arbitrary code.
GHSA-2cvg-w29m-j8xc
Arbitrary Code Execution in Processwire
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-24676 An issue found in ProcessWire 3.0.210 allows attackers to execute arbitrary code and install a reverse shell via the download_zip_url parameter when installing a new module. NOTE: this is disputed because exploitation requires that the attacker is able to enter requests as an admin; however, a ProcessWire admin is intentionally allowed to install any module that contains any arbitrary code. | CVSS3: 7.2 | 0% Низкий | около 2 лет назад | |
GHSA-2cvg-w29m-j8xc Arbitrary Code Execution in Processwire | CVSS3: 7.2 | 0% Низкий | около 2 лет назад |
Уязвимостей на страницу