CVE-2023-49328: Wolterskluwer B.point

High severity, CVSS 7.2. EPSS: 1% chance of exploitation in the next 30 days.

On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated system user can achieve remote code execution via Argument Injection in the server-to-server module.

Affected products

Published 2023-12-25. Last modified 2026-06-17.