PT-2023-26558 · Lucee · Lucee

Rootxharsh

·

Publicado

2023-08-15

·

Atualizado

2025-03-06

·

CVE-2023-38693

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lucee versions prior to 5.4.3.2 Lucee versions prior to 5.3.12.1
Description A security flaw has been discovered in Lucee, impacting all prior releases. New releases (5.4.3.2, 5.3.12.1) have been made to address the issue and enhance security.
Recommendations For versions prior to 5.4.3.2, update to version 5.4.3.2 to resolve the issue. For versions prior to 5.3.12.1, update to version 5.3.12.1 to resolve the issue.

Exploit

Correção

RCE

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-38693
GHSA-VWJX-MMWM-PWRF

Produtos afetados

Lucee