CVE-2023-39834: Command Injection
Published Aug 24, 2023
·Updated
PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via createfunction.
Affected Software
1 affected component
Pbootcms Pbootcms<3.2.0
Event History
Aug 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of the command injection vulnerability in PbootCMS?
The vulnerability ID of the command injection vulnerability in PbootCMS is CVE-2023-39834.
2
What is the severity of CVE-2023-39834?
The severity of CVE-2023-39834 is critical with a CVSS score of 9.8.
3
What is the affected software version of CVE-2023-39834?
The affected software version of CVE-2023-39834 is PbootCMS below v3.2.0.
4
How can the command injection vulnerability in PbootCMS be exploited?
The command injection vulnerability in PbootCMS can be exploited via create_function.
5
Is there a fix available for CVE-2023-39834?
Yes, upgrading PbootCMS to version 3.2.0 or above will fix the command injection vulnerability.