CVE-2023-46990: Critical severity sanluan publiccms vulnerability
Published Nov 20, 2023
·Updated
Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeReplace function.
Affected Software
1 affected component
PublicCMS publiccms=4.0.202302.e
Event History
Nov 20, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-46990?
The severity of CVE-2023-46990 is critical.
2
How does CVE-2023-46990 affect PublicCMS?
CVE-2023-46990 affects PublicCMS v.4.0.202302.e.
3
How can a remote attacker exploit CVE-2023-46990?
A remote attacker can exploit CVE-2023-46990 by executing arbitrary code via a crafted script to the writeReplace function.
4
Is there a fix available for CVE-2023-46990?
At the moment, there is no known fix available for CVE-2023-46990. It is recommended to follow the provided reference for any updates on the vulnerability.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-46990?
The Common Weakness Enumeration (CWE) ID for CVE-2023-46990 is 502.