CVE-2014-2302: Webedition CMS
Critical severity, CVSS 9.8. EPSS: 4.5% chance of exploitation in the next 30 days.
The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection attacks by intercepting a request to update.webedition.org.
Affected products
- Webedition Webedition CMS: before 6.2.7.0 (fixed in 6.2.7.0); from 6.3.0, before 6.3.8 (fixed in 6.3.8); version 6.2.7.0 only; version 6.3.8 only
Published 2018-07-19. Last modified 2026-06-17.