VYPR
Critical severity9.8NVD Advisory· Published Jul 19, 2018· Updated Jun 17, 2026

CVE-2014-2302

CVE-2014-2302

Description

The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection attacks by intercepting a request to update.webedition.org.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Webedition/CMSllm-create4 versions
    <6.2.7-s1, <6.3.8-s1+ 3 more
    • (no CPE)range: <6.2.7-s1, <6.3.8-s1
    • cpe:2.3:a:webedition:webedition_cms:*:*:*:*:*:*:*:*range: <6.2.7.0
    • cpe:2.3:a:webedition:webedition_cms:6.2.7.0:s1:*:*:*:*:*:*
    • cpe:2.3:a:webedition:webedition_cms:6.3.8:s1:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.