CVE-2026-79362
N/A
N/A
Summary
Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated low-privileged user can inject PHP into executable cache files generated by WoltLab Suite Core. Attacker-controlled data can terminate the nowdoc prematurely and inject arbitrary PHP Code.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
References
- https://www.woltlab.com/community/thread/319263-update-woltlab-suite-6-2-6-6-1-23/
- https://github.com/WoltLab/WCF/commit/c19789dbcc15663c648db1b196b6e6b05265b121
- https://www.woltlab.com/community/thread/319264-aktualisierung-woltlab-suite-6-2-6-6-1-23/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.