What the vulnerability does
01Description
Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
Explanation of Vulnerability in Simple Terms
Betheme versions up to 28.4.2 contain a code injection vulnerability that allows authenticated users with low privileges to inject and execute arbitrary code on the site. The vulnerability affects the entire application scope due to changed scope impact. An attacker can read sensitive data, modify site content, or disrupt service availability.
What an attacker can do
Run arbitrary code on the site, read sensitive data, modify content, or disable the site.
Potential impact on your site
Any low-privilege user account (subscriber, contributor, etc.) can compromise the entire site.
Conditions required to exploit
Attacker must have a low-privilege authenticated account and network access to the site.
Key dates
External resources
Related vulnerabilities