Description
WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attackers can craft a specially designed ZIP module with embedded PHP reverse shell code to gain remote system access when the module is installed.
Problem types
CWE-434: Unrestricted Upload of File with Dangerous Type
Product status
1.6.3
Credits
Swammers8
References
www.exploit-db.com/exploits/52132 (ExploitDB-52132)
wbce-cms.org/ (WBCE CMS Homepage)
github.com/WBCE/WBCE_CMS (WBCE CMS GitHub Repository)
youtu.be/Dhg5gRe9Dzs?si=-WQoiWU1yqvYNz1e (YouTube Demonstration)
github.com/Swammers8/WBCE-v1.6.3-Authenticated-RCE (Swammers8 GitHub Repository)
www.vulncheck.com/...remote-code-execution-via-module-upload (VulnCheck Advisory: WBCE CMS 1.6.3 Authenticated Remote Code Execution via Module Upload)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.