CVE-2023-36994

CRITICAL

TravianZ <8.3.4-8.3.3 - Code Injection

Title source: llm
STIX 2.1

Description

In TravianZ 8.3.4 and 8.3.3, Incorrect Access Control in the installation script allows an attacker to overwrite the server configuration and inject PHP code.

References (1)

Core 1
Core References
Exploit, Third Party Advisory
https://bramdoessecurity.com/travianz-hacked/

Scores

CVSS v3 9.8
EPSS 0.0074
EPSS Percentile 50.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-863
Status published
Products (2)
travianz_project/travianz 8.3.3
travianz_project/travianz 8.3.4
Published Jul 07, 2023
Tracked Since Feb 18, 2026