PT-2026-2429 · Webgrind · Webgrind

Rafael Pedrero

·

Published

2026-01-13

·

Updated

2026-01-14

·

CVE-2023-54339

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Webgrind version 1.1
Description Webgrind version 1.1 contains a remote command execution issue. Unauthenticated attackers can inject OS commands through the dataFile parameter in the ''index.php'' file. Attackers can execute arbitrary system commands by manipulating the dataFile parameter, for example, using a payload like '0%27%26calc.exe%26%27' to execute commands on the target system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-54339

Affected Products

Webgrind