PT-2026-2412 · Wbce Cms · Wbce Cms

Antonio Cuomo

·

Published

2026-01-13

·

Updated

2026-01-20

·

CVE-2022-50936

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WBCE CMS version 1.5.2
Description The software contains an authenticated remote code execution issue. Attackers can upload malicious droplets through the admin panel. Specifically, authenticated attackers can exploit the droplet upload functionality within the admin tools to create and execute arbitrary PHP code by crafting a specially designed zip file payload. The vulnerable functionality is related to the droplet upload process.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the droplet upload functionality in the admin panel.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-50936

Affected Products

Wbce Cms