peter bassill · operator
$ cve CVE-2023-38692 JSON

CVE-2023-38692

9.8
CRITICAL · CVSS 3.1 · EPSS 3.4% (pctl 88)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

CloudExplorer Lite is an open source, lightweight cloud management platform. Versions prior to 1.3.1 contain a command injection vulnerability in the installation function in module management. The vulnerability has been fixed in v1.3.1. There are no known workarounds aside from upgrading.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.39% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2023-08-04
Last modified2026-06-17

Affected (1)

VendorProduct
fit2cloudcloudexplorer lite

References

→ the Explorer  ·  watch your stack  ·  NVD