CVE-2024-58283 PUBLISHED

WBCE CMS 1.6.2 Remote Code Execution via Elfinder File Upload

Assigner: VulnCheck
Reserved: 10.12.2025 Published: 10.12.2025 Updated: 11.12.2025

WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the Elfinder file manager. Attackers can exploit the file upload functionality in the elfinder connector to upload a web shell and execute arbitrary system commands through a user-controlled parameter.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor wbce
Product WBCE CMS
Versions Default: unaffected
  • Version 1.6.2 is affected

Credits

  • Ahmet Ümit BAYRAM finder

References

Problem Types

  • CWE-434: Unrestricted Upload of File with Dangerous Type CWE