Description
A local file inclusion vulnerability has been found in WPN-XM Serverstack affecting version 0.8.6, which would allow an unauthenticated user to perform a local file inclusion (LFI) via the /tools/webinterface/index.php?page parameter by sending a GET request. This vulnerability could lead to the loading of a PHP file on the server, leading to a critical webshell exploit.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
There is no reported solution at this time.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54444 | A local file inclusion vulnerability has been found in WPN-XM Serverstack affecting version 0.8.6, which would allow an unauthenticated user to perform a local file inclusion (LFI) via the /tools/webinterface/index.php?page parameter by sending a GET request. This vulnerability could lead to the loading of a PHP file on the server, leading to a critical webshell exploit. |
References
History
No history.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-05T15:09:56.489Z
Reserved: 2023-08-29T08:19:29.525Z
Link: CVE-2023-4591
Updated: 2024-08-02T07:31:06.612Z
Status : Modified
Published: 2023-11-03T12:15:08.800
Modified: 2024-11-21T08:35:30.037
Link: CVE-2023-4591
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD