RULE(RULE ID:337988)

Rule General Information
Release Date: 2024-05-07
Rule Name: WBCE 1.6.0 SQL injection Vulnerability (CVE-2023-39796)
Severity:
CVE ID:
Rule Protection Details
Description: SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_RECORD_TABLE parameter.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference: https://forum.wbce.org/viewtopic.php?pid=42046#p42046
https://github.com/WBCE/WBCE_CMS/releases/tag/1.6.1
https://pastebin.com/PBw5AvGp
Solutions
Please contact the software vendor to update the software patch.