Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2023-32548

OS command injection vulnerability exists in WPS Office version 10.8.0.6186. If a remote attacker who can conduct a man-in-the-middle attack connects the product to a malicious server and sends a specially crafted data, an arbitrary OS command may be executed on the system where the product is installed.

  • Published: Jun 13, 2023
  • Updated: Jun 22, 2023
  • CVE: CVE-2023-32548
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 8.1
  • AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CWEs:

OWASP TOP 10: