CVE-2022-50936

Source
https://cve.org/CVERecord?id=CVE-2022-50936
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50936.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-50936
Published
2026-01-13T22:52:02Z
Modified
2026-08-12T03:51:17Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
WBCE CMS 1.5.2 - Remote Code Execution (RCE) (Authenticated)
Details

WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the admin panel. Authenticated attackers can exploit the droplet upload functionality in the admin tools to create and execute arbitrary PHP code by crafting a specially designed zip file payload.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-434"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50936.json"
}
References

Affected packages

Git / github.com/wbce/wbce_cms

Affected ranges

Type
GIT
Repo
https://github.com/wbce/wbce_cms
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:wbce:wbce_cms:1.5.2:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.5.2"
        },
        {
            "last_affected": "1.5.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_STRING"
    ]
}

Affected versions

1.*
1.5.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50936.json"