CVE-2023-47621 is a critical vulnerability affecting the duncanmcclean guest_entries PHP library, allowing authenticated users to upload malicious PHP files due to insufficient file type validation. This flaw carries a high CVSS score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating it can lead to remote code execution, compromising the confidentiality, integrity, and availability of the server. While there are no known public exploits, Metasploit modules, or active exploitation, users are strongly advised to upgrade to version 3.1.2 immediately as there are no workarounds. Despite its severity, there is currently no significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1.3CPE matchmatch criteria | cpe:2.3:a:duncanmcclean:guest_entries:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.