CVE-2023-39796 Information

Description

SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_RECORD_TABLE parameter.

Reference

https://github.com/WBCE/WBCE_CMS/releases/tag/1.6.1 https://forum.wbce.org/viewtopic.php?pid=42046#p42046 https://pastebin.com/PBw5AvGp

Share on: