CVE-2023-49328: Wolterskluwer B.point
High severity, CVSS 7.2. EPSS: 1% chance of exploitation in the next 30 days.
On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated system user can achieve remote code execution via Argument Injection in the server-to-server module.
Affected products
- Wolterskluwer B.point: version 23.70.00 only
Published 2023-12-25. Last modified 2026-06-17.