---
id: CVE-2024-58283
title: >-
  WBCE CMS version 1.6.2 contains a remote code execution vulnerability that
  allows authenticated attackers to upload malicious PHP files through the
  Elfinder file manager
summary: >-
  WBCE CMS version 1.6.2 contains a remote code execution vulnerability that
  allows authenticated attackers to upload malicious PHP files through the
  Elfinder file manager. Attackers can exploit the file upload functionality in
  the elfinde…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
vendor: wbce
product: wbce_cms
affected:
  - wbce_cms = 1.6.2
published: '2025-12-10'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T21:10:00.130'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-58283'
references:
  - url: 'https://github.com/WBCE/WBCE_CMS/archive/refs/tags/1.6.2.zip'
    label: disclosure@vulncheck.com
  - url: 'https://wbce-cms.org/'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/52039'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/wbce-cms-remote-code-execution-via-elfinder-file-upload
    label: disclosure@vulncheck.com
  - url: 'https://github.com/WBCE/WBCE_CMS/archive/refs/tags/1.6.2.zip'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00665
epssPercentile: 0.49754
ingestedAt: '2026-09-26T21:38:01.499Z'
---

## Overview

WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the Elfinder file manager. Attackers can exploit the file upload functionality in the elfinder connector to upload a web shell and execute arbitrary system commands through a user-controlled parameter.

## Affected

- `wbce_cms = 1.6.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
