GHSA-hh3c-hgv7-gg2rHighCVSS 8.8
Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and...
🔗 CVE IDs covered (1)
📋 Description
Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated low-privileged user can inject PHP into executable cache files generated by WoltLab Suite Core. Attacker-controlled data can terminate the nowdoc prematurely and inject arbitrary PHP Code.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-79362
- https://github.com/WoltLab/WCF/commit/c19789dbcc15663c648db1b196b6e6b05265b121
- https://www.woltlab.com/community/thread/319263-update-woltlab-suite-6-2-6-6-1-23
- https://www.woltlab.com/community/thread/319264-aktualisierung-woltlab-suite-6-2-6-6-1-23
- https://github.com/advisories/GHSA-hh3c-hgv7-gg2r