Impact
Certain versions of WoltLab Suite Core are vulnerable to remote code execution through cache poisoning. An authenticated low‑privileged user can inject arbitrary PHP code into cache files that the application later executes. Attacker‑controlled data can prematurely terminate the nowdoc syntax, allowing malicious PHP to be written into executable cache files. Once these files are processed, the injected code runs with the privileges of the web server process, giving the attacker the ability to perform actions that the web server would normally permit.
Affected Systems
WoltLab Suite Core versions 6.1.0 through 6.1.22 and 6.2.0 through 6.2.5 are affected. The vulnerability exists in installations running WCF from 6.1.0 up to, but not including, 6.1.23, and from 6.2.0 up to, but not including, 6.2.6. Only systems that have not been upgraded to at least 6.1.23 or 6.2.6 are susceptible.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1 % shows a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector requires authenticated low‑privileged user access, making random attacks less likely, but successful exploitation results in uncompromised code execution on the server. Based on the description, it is inferred that the attacker would need to submit specially crafted data that terminates the nowdoc prematurely; once achieved, malicious PHP code would run with web‑server privileges.
OpenCVE Enrichment