CVE-2023-4591 is a critical local file inclusion (LFI) vulnerability affecting WPN-XM Serverstack version 0.8.6. An unauthenticated attacker can exploit this flaw by manipulating the 'page' parameter in the /tools/webinterface/index.php endpoint via a GET request. This allows for the loading of arbitrary PHP files, potentially leading to a webshell and complete compromise of the server. The vulnerability carries a CVSS score of 9.8 (Critical), indicating it is easily exploitable over the network with low attack complexity and no user interaction required, resulting in high impact to confidentiality, integrity, and availability. Its EPSS score is low, suggesting a minimal probability of exploitation in the wild, and it is not listed in CISA's KEV catalog. Currently, there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, and it is not known to be actively exploited. Despite this, the vulnerability has garnered some community discussion and media coverage, indicating a degree of awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.8.6CPE matchmatch criteria | cpe:2.3:a:wpn-xm:wpn-xm:0.8.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.