CVE-2014-2302: Webedition CMS

Critical severity, CVSS 9.8. EPSS: 4.5% chance of exploitation in the next 30 days.

The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection attacks by intercepting a request to update.webedition.org.

Affected products

  • Webedition Webedition CMS: before 6.2.7.0 (fixed in 6.2.7.0); from 6.3.0, before 6.3.8 (fixed in 6.3.8); version 6.2.7.0 only; version 6.3.8 only

Published 2018-07-19. Last modified 2026-06-17.