CVE-2023-4591
HIGHWPN-XM Serverstack 0.8.6 - Local File Inclusion via page Parameter
Title source: manualDescription
A local file inclusion vulnerability has been found in WPN-XM Serverstack affecting version 0.8.6, which would allow an unauthenticated user to perform a local file inclusion (LFI) via the /tools/webinterface/index.php?page parameter by sending a GET request. This vulnerability could lead to the loading of a PHP file on the server, leading to a critical webshell exploit.
References (1)
Core 1
Core References
Scores
CVSS v3
7.5
EPSS
0.0062
EPSS Percentile
44.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-829
Status
published
Products (1)
wpn-xm/wpn-xm
0.8.6
Published
Nov 03, 2023
Tracked Since
Feb 18, 2026