CVE-2023-3607: kodbox WebConsole Plug-In webconsole.php.txt Execute os command injection
A vulnerability was found in kodbox 1.26. It has been declared as critical. This vulnerability affects the function Execute of the file webconsole.php.txt of the component WebConsole Plug-In. The manipulation leads to os command injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-233476. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3607?
CVE-2023-3607 is a critical vulnerability found in kodbox 1.26, specifically in the Execute function of the file webconsole.php.txt of the WebConsole Plug-In component. It allows for OS command injection.
How severe is CVE-2023-3607?
CVE-2023-3607 is classified as a high severity vulnerability with a severity value of 8.
How does CVE-2023-3607 affect Kodbox?
CVE-2023-3607 affects Kodbox 1.26, allowing for OS command injection through the Execute function of the WebConsole Plug-In component.
Is there a fix for CVE-2023-3607?
At the moment, there is no known fix for CVE-2023-3607. It is recommended to update to a patched version of Kodbox once it becomes available.
What is the Common Weakness Enumeration (CWE) associated with CVE-2023-3607?
CVE-2023-3607 is associated with CWE-77 (Improper Neutralization of Special Elements used in a Command) and CWE-78 (Improper Neutralization of Special Elements used in an OS Command).