CVE-2023-54339

Webgrind 1.1 contains a remote command execution vulnerability that allows unauthenticated attackers to inject OS commands via the dataFile parameter in index.php. Attackers can execute arbitrary system commands by manipulating the dataFile parameter, such as using payload '0%27%26calc.exe%26%27' to execute commands on the target system.
Configurations

No configuration.

History

14 Jan 2026, 20:16

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/51074 - () https://www.exploit-db.com/exploits/51074 -

13 Jan 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 23:16

Updated : 2026-01-14 20:16


NVD link : CVE-2023-54339

Mitre link : CVE-2023-54339

CVE.ORG link : CVE-2023-54339


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')