CVE-2023-48699 is a critical Remote Code Execution (RCE) vulnerability affecting the fastbots library, a tool for bot and scraper development using Selenium and the Page Object Model, specifically versions prior to 0.1.5. An attacker can exploit this by modifying the locators.ini file with malicious Python code, which is then executed without proper validation within the __locator__ function in page.py. This vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating a severe risk with a network attack vector, low attack complexity, and high impacts on confidentiality, integrity, and availability. No user interaction is required for exploitation. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.1.5CPE matchmatch criteria | cpe:2.3:a:ubertidavide:fastbots:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.