CVE-2021-47788

WebsiteBaker 2.13.0 contains an authenticated remote code execution vulnerability that allows users with language editing permissions to execute arbitrary code. Attackers can exploit the language installation endpoint by manipulating language installation parameters to achieve remote code execution on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:websitebaker:websitebaker:2.13.0:*:*:*:*:*:*:*

History

17 Jun 2026, 04:18

Type Values Removed Values Added
Summary
  • (es) WebsiteBaker 2.13.0 contiene una vulnerabilidad de ejecución remota de código autenticada que permite a usuarios con permisos de edición de idioma ejecutar código arbitrario. Los atacantes pueden explotar el endpoint de instalación de idioma manipulando los parámetros de instalación de idioma para lograr la ejecución remota de código en el servidor.

30 Jan 2026, 01:02

Type Values Removed Values Added
References () https://websitebaker.org/ - () https://websitebaker.org/ - Product
References () https://www.exploit-db.com/exploits/50310 - () https://www.exploit-db.com/exploits/50310 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/websitebaker-remote-code-execution-rce-authenticated - () https://www.vulncheck.com/advisories/websitebaker-remote-code-execution-rce-authenticated - Third Party Advisory
First Time Websitebaker
Websitebaker websitebaker
CPE cpe:2.3:a:websitebaker:websitebaker:2.13.0:*:*:*:*:*:*:*

16 Jan 2026, 22:16

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/50310 - () https://www.exploit-db.com/exploits/50310 -

16 Jan 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-16 00:16

Updated : 2026-06-17 04:18


NVD link : CVE-2021-47788

Mitre link : CVE-2021-47788

CVE.ORG link : CVE-2021-47788


JSON object : View

Products Affected

websitebaker

  • websitebaker
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type