Back

CRITICAL

Inclusion of Functionality from Untrusted Control Sphere in WPN-XM Serverstack

Published Nov 3, 2023

Description

A local file inclusion vulnerability has been found in WPN-XM Serverstack affecting version 0.8.6, which would allow an unauthenticated user to perform a local file inclusion (LFI) via the /tools/webinterface/index.php?page parameter by sending a GET request. This vulnerability could lead to the loading of a PHP file on the server, leading to a critical webshell exploit.

Affected products

Remediation

Vendor solution

There is no reported solution at this time.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Nov 3, 2023
Updated Sep 5, 2024
Reserved Aug 29, 2023
CISA Vulnrichment
Updated Sep 5, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a