First published: Fri Nov 10 2023(Updated: )
SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_RECORD_TABLE parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wbce CMS | =1.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-39796 is critical with a score of 9.8.
CVE-2023-39796 allows remote unauthenticated attackers to execute arbitrary code through SQL injection in the miniform module of WBCE CMS v.1.6.0.
Yes, WBCE CMS version 1.6.0 is affected by CVE-2023-39796.
To fix CVE-2023-39796, upgrade to WBCE CMS version 1.6.1 or later.
More information about CVE-2023-39796 can be found at the following references: [INSERT LINKS].