CVE-2014-1683 describes a remote command execution vulnerability in SkyBlueCanvas CMS versions prior to 1.1 r248-04. Attackers can exploit this by injecting shell metacharacters into various parameters within the bashMail function when the 'pid' parameter is set to 4. This vulnerability carries a CVSS score of 6.8, indicating moderate complexity but allowing for complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog, public exploit modules exist for Metasploit and ExploitDB, and its EPSS score of 0.7853 suggests a high likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.1_r248-03CPE matchmatch criteria | cpe:2.3:a:skybluecanvas:skybluecanvas:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.