Vulnerability CVE-2023-39796


Published: 2023-11-10

Description:
SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_RECORD_TABLE parameter.

 References:
https://github.com/WBCE/WBCE_CMS/releases/tag/1.6.1
https://forum.wbce.org/viewtopic.php?pid=42046#p42046
https://pastebin.com/PBw5AvGp

Copyright 2026, cxsecurity.com

 

Back to Top