CVE-2023-51350: Ujcms

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the X-Forwarded-For function in the header.

Affected products

  • Ujcms Ujcms: version 8.0.2 only

Published 2024-01-11. Last modified 2026-06-17.