Vulnerability Description
outdoorbits little-backup-box (aka Little Backup Box) before f39f91c allows remote attackers to execute arbitrary code because the PHP extract function is used for untrusted input.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Outdoorbits | Little Backup Box | < 2023-10-03 |
References
- https://github.com/outdoorbits/little-backup-box/commit/f39f91cd05544b3eb18b5989Patch
- https://www.php.net/manual/en/function.extractProduct
- https://github.com/outdoorbits/little-backup-box/commit/f39f91cd05544b3eb18b5989Patch
- https://www.php.net/manual/en/function.extractProduct
FAQ
What is CVE-2023-52262?
CVE-2023-52262 is a vulnerability with a CVSS score of 9.8 (CRITICAL). outdoorbits little-backup-box (aka Little Backup Box) before f39f91c allows remote attackers to execute arbitrary code because the PHP extract function is used for untrusted input.
How severe is CVE-2023-52262?
CVE-2023-52262 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-52262?
Check the references section above for vendor advisories and patch information. Affected products include: Outdoorbits Little Backup Box.