CVE-2021-47788: WebsiteBaker 2.13.0 - Remote Code Execution (RCE) (Authenticated)
WebsiteBaker 2.13.0 contains an authenticated remote code execution vulnerability that allows users with language editing permissions to execute arbitrary code. Attackers can exploit the language installation endpoint by manipulating language installation parameters to achieve remote code execution on the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47788?
CVE-2021-47788 is rated as a high-severity vulnerability due to its remote code execution potential.
How do I fix CVE-2021-47788?
To fix CVE-2021-47788, update to the latest version of WebsiteBaker that addresses this vulnerability.
Who is affected by CVE-2021-47788?
CVE-2021-47788 affects all users of WebsiteBaker version 2.13.0 with language editing permissions.
What types of attacks can exploit CVE-2021-47788?
Attackers can exploit CVE-2021-47788 by manipulating the language installation endpoint to execute arbitrary code.
Is authentication required to exploit CVE-2021-47788?
Yes, exploitation of CVE-2021-47788 requires authentication with language editing permissions.