WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the Elfinder file manager. Attackers can exploit the file upload functionality in the elfinder connector to upload a web shell and execute arbitrary system commands through a user-controlled parameter.
History

Thu, 11 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 11 Dec 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Wbce
Wbce wbce Cms
Vendors & Products Wbce
Wbce wbce Cms

Wed, 10 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
Description WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the Elfinder file manager. Attackers can exploit the file upload functionality in the elfinder connector to upload a web shell and execute arbitrary system commands through a user-controlled parameter.
Title WBCE CMS 1.6.2 Remote Code Execution via Elfinder File Upload
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-10T21:14:54.713Z

Updated: 2025-12-11T18:51:34.057Z

Reserved: 2025-12-10T14:35:24.455Z

Link: CVE-2024-58283

cve-icon Vulnrichment

Updated: 2025-12-11T15:44:23.987Z

cve-icon NVD

Status : Received

Published: 2025-12-10T22:16:20.267

Modified: 2025-12-11T19:15:52.587

Link: CVE-2024-58283

cve-icon Redhat

No data.