Description
Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject system commands through PHP page creation. Attackers can create a new PHP page with malicious system commands in the description field to execute arbitrary commands on the server.
Problem types
Improper Control of Generation of Code ('Code Injection')
Product status
Credits
Mirabbas Ağalarov
References
www.exploit-db.com/exploits/51661
www.exploit-db.com/exploits/51661 (ExploitDB-51661)
www.webedition.org/ (webEdition Product Webpage)
www.vulncheck.com/...te-code-execution-via-php-page-creation (VulnCheck Advisory: Webedition CMS v2.9.8.8 Remote Code Execution via PHP Page Creation)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.