Record summary

CVE-2022-46020 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 17, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryCRITICALWBCE CMS v1.5.4 - Remote Code ExecutionCVSS 9.8

WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.

Remediation

Upgrade to a patched version of WBCE CMS v1.5.5 or later to mitigate this vulnerability.

WeaknessesCWE-434
Authorstheamanrawat
Template tagscvecve2022rcewbcecmsauthenticatedintrusivevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:wbce:wbce_cms:1.5.4:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2