What the vulnerability does
01Description
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
Explanation of Vulnerability in Simple Terms
Cwicly versions up to 1.4.4 contain a code injection vulnerability that allows authenticated users with low privileges to inject and execute arbitrary code on the site. The vulnerability has network-wide scope, meaning an attacker can compromise the entire installation. An authenticated attacker can read sensitive data, modify site content, and disrupt service availability.
What an attacker can do
Run arbitrary code on the site, read sensitive data, modify content, and disrupt availability.
Potential impact on your site
Any authenticated user, even with minimal permissions, can compromise your entire site and its data.
Conditions required to exploit
Attacker must have a low-privilege authenticated account; no user interaction required.
Key dates
External resources
Related vulnerabilities