github.com
https://github.com/10vexh/Vulnerability/blob/main/WBCE%20CMS%20v1.5.4%20getshell.pdf CVE-2022-46020
CRITICALNuclei
WBCE CMS v1.5.4 - Remote Code Execution
Record summary
CVE-2022-46020 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 17, 2025 · Source: CVE List
Nuclei templates
1ProjectDiscoveryCRITICALWBCE CMS v1.5.4 - Remote Code ExecutionCVSS 9.8
WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
Remediation
Upgrade to a patched version of WBCE CMS v1.5.5 or later to mitigate this vulnerability.
WeaknessesCWE-434
Authorstheamanrawat
Template tagscvecve2022rcewbcecmsauthenticatedintrusivevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:wbce:wbce_cms:1.5.4:*:*:*:*:*:*:*
https://github.com/WBCE/WBCE_CMS https://github.com/10vexh/Vulnerability/blob/main/WBCE%20CMS%20v1.5.4%20getshell.pdf https://nvd.nist.gov/vuln/detail/CVE-2022-46020
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-46020