Impact
WebsiteBaker CMS versions earlier than 2.13.10 allow administrators to upload any file during module installation. A crafted ZIP containing a PHP webshell is extracted into a publicly accessible modules/ directory, letting the attacker run the shell after the upload. The vulnerability provides uncontrolled code execution for the web application and opens the site to full compromise.
Affected Systems
The flaw affects the WebsiteBaker CMS produced by WebsiteBaker Org e.V. Only installations running a version older than 2.13.10 are impacted. No specific CPE strings are listed, but the affected product is the CMS itself.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. Because an authenticated administrator is required to upload the archive, the attack vector is limited to privileged users accessing the administration console. Once the module is deployed, any unprivileged user can invoke the webshell via HTTP, providing remote code execution. The EPSS score is not available and the flaw is not included in the CISA KEV catalog, but the high CVSS still signals a significant risk if the system is not patched.
OpenCVE Enrichment