CVE-2023-32548: Command Injection
OS command injection vulnerability exists in WPS Office version 10.8.0.6186. If a remote attacker who can conduct a man-in-the-middle attack connects the product to a malicious server and sends a specially crafted data, an arbitrary OS command may be executed on the system where the product is installed.
Affected Software
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2023-32548.
What software is affected by this vulnerability?
WPS Office version 10.8.0.6186 is affected by this vulnerability.
What is the severity of CVE-2023-32548?
The severity of CVE-2023-32548 is high with a CVSS score of 8.1.
What is the description of CVE-2023-32548?
CVE-2023-32548 is an OS command injection vulnerability that exists in WPS Office version 10.8.0.6186.
How can an attacker exploit CVE-2023-32548?
An attacker who can conduct a man-in-the-middle attack can exploit CVE-2023-32548 by connecting the product to a malicious server and sending a specially crafted data.