WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the admin panel. Authenticated attackers can exploit the droplet upload functionality in the admin tools to create and execute arbitrary PHP code by crafting a specially designed zip file payload.
Metrics
Affected Vendors & Products
References
History
Tue, 13 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the admin panel. Authenticated attackers can exploit the droplet upload functionality in the admin tools to create and execute arbitrary PHP code by crafting a specially designed zip file payload. | |
| Title | WBCE CMS 1.5.2 - Remote Code Execution (RCE) (Authenticated) | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-13T22:52:02.201Z
Reserved: 2026-01-11T13:34:26.329Z
Link: CVE-2022-50936
No data.
Status : Received
Published: 2026-01-13T23:15:58.703
Modified: 2026-01-13T23:15:58.703
Link: CVE-2022-50936
No data.
OpenCVE Enrichment
No data.