PT-2026-2412 · Wbce Cms · Wbce Cms

Antonio Cuomo

·

Publicado

2026-01-13

·

Atualizado

2026-01-20

·

CVE-2022-50936

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WBCE CMS version 1.5.2
Description The software contains an authenticated remote code execution issue. Attackers can upload malicious droplets through the admin panel. Specifically, authenticated attackers can exploit the droplet upload functionality within the admin tools to create and execute arbitrary PHP code by crafting a specially designed zip file payload. The vulnerable functionality is related to the droplet upload process.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the droplet upload functionality in the admin panel.

Exploit

Correção

RCE

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-50936

Produtos afetados

Wbce Cms