PT-2026-2412 · Wbce Cms · Wbce Cms
Antonio Cuomo
·
Published
2026-01-13
·
Updated
2026-01-20
·
CVE-2022-50936
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WBCE CMS version 1.5.2
Description
The software contains an authenticated remote code execution issue. Attackers can upload malicious droplets through the admin panel. Specifically, authenticated attackers can exploit the droplet upload functionality within the admin tools to create and execute arbitrary PHP code by crafting a specially designed zip file payload. The vulnerable functionality is related to the droplet upload process.
Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the droplet upload functionality in the admin panel.
Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wbce Cms