PT-2024-12039 · Unknown · Processwire

Published

2024-01-24

·

Updated

2025-10-17

·

CVE-2023-24676

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ProcessWire version 3.0.210
Description An issue in ProcessWire allows attackers to execute arbitrary code and install a reverse shell via the download zip url parameter when installing a new module. This issue is disputed as it requires the attacker to have admin privileges, which intentionally allows the installation of any module containing arbitrary code.
Recommendations For ProcessWire version 3.0.210, as a temporary workaround, consider restricting the use of the download zip url parameter when installing new modules to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2023-24676
GHSA-2CVG-W29M-J8XC

Affected Products

Processwire