PT-2025-51301 · Unknown · Webedition Cms

·

CVE-2023-53883

·

Publicado

2025-12-15

·

Atualizado

2025-12-21

CVSS v4.0

8.6

Alta

VetorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Webedition CMS version 2.9.8.8
Description Webedition CMS version 2.9.8.8 has a flaw that permits authenticated attackers to execute system commands remotely. This is achieved by creating a new PHP page and inserting malicious system commands within the description field. This allows for arbitrary command execution on the server. The vulnerable functionality involves the creation of PHP pages. The affected parameter is the description field during PHP page creation.
Recommendations Apply a fix that prevents the execution of system commands within the description field during PHP page creation.

Exploit

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-53883

Produtos afetados

Webedition Cms