Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-46253— Remote code execution in Squidex

Quick assessment

Affected
Squidex squidex
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

squidex是一款 Headless CMS 和内容管理中心。 squidex 7.8.2版本存在路径遍历漏洞,该漏洞源于backup restore功能存在任意文件写入漏洞。

CVSS 9.1 · Critical EPSS 1.54% · P74
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-46253

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Remote code execution in Squidex
Source: CVE Program / CVE List V5
Vulnerability Description
Squidex is an open source headless CMS and content management hub. Affected versions are subject to an arbitrary file write vulnerability in the backup restore feature which allows an authenticated attacker to gain remote code execution (RCE). Squidex allows users with the `squidex.admin.restore` permission to create and restore backups. Part of these backups are the assets uploaded to an App. For each asset, the backup zip archive contains a `.asset` file with the actual content of the asset as well as a related `AssetCreatedEventV2` event, which is stored in a JSON file. Amongst other things, the JSON file contains the event type (`AssetCreatedEventV2`), the ID of the asset (`46c05041-9588-4179-b5eb-ddfcd9463e1e`), its filename (`test.txt`), and its file version (`0`). When a backup with this event is restored, the `BackupAssets.ReadAssetAsync` method is responsible for re-creating the asset. For this purpose, it determines the name of the `.asset` file in the zip archive, reads its content, and stores the content in the filestore. When the asset is stored in the filestore via the UploadAsync method, the assetId and fileVersion are passed as arguments. These are further passed to the method GetFileName, which determines the filename where the asset should be stored. The assetId is inserted into the filename without any sanitization and an attacker with squidex.admin.restore privileges to run arbitrary operating system commands on the underlying server (RCE).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5
Vulnerability Title
squidex 路径遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
squidex是一款 Headless CMS 和内容管理中心。 squidex 7.8.2版本存在路径遍历漏洞,该漏洞源于backup restore功能存在任意文件写入漏洞。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
Squidex squidex < 7.9.0 -

II. Public POCs for CVE-2023-46253

# POC Description Source Link Shenlong Link
AI-Generated POC Verified env Premium
Qwen3.6-35B-A3B · 9492 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2023-46253

请登录查看更多情报信息。

Vendor Advisories for CVE-2023-46253 (1)

Same Patch Batch · Squidex · 2023-11-07 · 3 CVEs total

CVE-2023-46252 6.8 MEDIUM Cross-Site Scripting (XSS) via postMessage Handler in Squidex
CVE-2023-46744 5.4 MEDIUM Stored Cross-site Scripting in Squidex

IV. Related Vulnerabilities

V. Comments for CVE-2023-46253

No comments yet


Leave a comment