CVE-2023-46253 is an arbitrary file write vulnerability in Squidex, an open-source headless CMS, affecting versions that allow authenticated users with 'squidex.admin.restore' permissions to restore backups. This flaw arises from insufficient sanitization of asset IDs during backup restoration, enabling an attacker to inject arbitrary operating system commands. Rated 7.2 HIGH (CVSSv3.1), this vulnerability allows a high-privileged attacker to achieve Remote Code Execution (RCE) with high impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.8.2CPE matchmatch criteria | cpe:2.3:a:squidex.io:squidex:7.8.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.