WebsiteBaker 2.13.0 contains an authenticated remote code execution vulnerability that allows users with language editing permissions to execute arbitrary code. Attackers can exploit the language installation endpoint by manipulating language installation parameters to achieve remote code execution on the server.
References
| Link | Resource |
|---|---|
| https://websitebaker.org/ | Product |
| https://www.exploit-db.com/exploits/50310 | Exploit VDB Entry |
| https://www.vulncheck.com/advisories/websitebaker-remote-code-execution-rce-authenticated | Third Party Advisory |
| https://www.exploit-db.com/exploits/50310 | Exploit VDB Entry |
Configurations
History
No history.
Information
Published : 2026-01-16 00:16
Updated : 2026-01-30 01:02
NVD link : CVE-2021-47788
Mitre link : CVE-2021-47788
CVE.ORG link : CVE-2021-47788
JSON object : View
Products Affected
websitebaker
- websitebaker
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
