{"id":"CVE-2023-24676","details":"An issue found in ProcessWire 3.0.210 allows attackers to execute arbitrary code and install a reverse shell via the download_zip_url parameter when installing a new module. NOTE: this is disputed because exploitation requires that the attacker is able to enter requests as an admin; however, a ProcessWire admin is intentionally allowed to install any module that contains any arbitrary code.","aliases":["GHSA-2cvg-w29m-j8xc"],"modified":"2026-08-12T03:51:37.067026336Z","published":"2024-01-24T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/24xxx/CVE-2023-24676.json","cna_assigner":"mitre","isDisputed":true},"references":[{"type":"WEB","url":"https://medium.com/%40cupc4k3/reverse-shell-via-remote-file-inlusion-in-proccesswire-cms-a8fa5ace3255"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/24xxx/CVE-2023-24676.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-24676"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/processwire/processwire","events":[{"introduced":"6ff498f503db118d5b6c190b35bd937b38b80a77"},{"last_affected":"6ff498f503db118d5b6c190b35bd937b38b80a77"}],"database_specific":{"cpe":"cpe:2.3:a:processwire:processwire:3.0.210:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.0.210"},{"last_affected":"3.0.210"}],"source":"CPE_STRING"}}],"versions":["3.0.210"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-24676.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}