CVE-2024-58283

Source
https://cve.org/CVERecord?id=CVE-2024-58283
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58283.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-58283
Published
2025-12-10T21:14:54.713Z
Modified
2026-07-15T01:49:04.326044911Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
WBCE CMS 1.6.2 Remote Code Execution via Elfinder File Upload
Details

WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the Elfinder file manager. Attackers can exploit the file upload functionality in the elfinder connector to upload a web shell and execute arbitrary system commands through a user-controlled parameter.

Database specific
{
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/58xxx/CVE-2024-58283.json",
    "cwe_ids": [
        "CWE-434"
    ]
}
References

Affected packages

Git / github.com/wbce/wbce_cms

Affected ranges

Type
GIT
Repo
https://github.com/wbce/wbce_cms
Events
Database specific
{
    "cpe": "cpe:2.3:a:wbce:wbce_cms:1.6.2:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.6.2"
        },
        {
            "last_affected": "1.6.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_STRING"
    ]
}

Affected versions

1.*
1.6.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58283.json"