THREATPORT/VULNERABILITY/CVE-2023-33177
HIGH SEVERITY

CVE-2023-33177

Xibo vulnerability

CVSS
8.8
EPSS
7.1%
EPSS pct
94th
Exploited
No known
Xibo is a content management system (CMS). A path traversal vulnerability exists in the Xibo CMS whereby a specially crafted zip file can be uploaded to the CMS via the layout import function by an authenticated user which would allow creation of files outside of the CMS library directory as the webserver user. This can be used to upload a PHP webshell inside the web root directory and achieve remote code execution as the webserver user. Users should upgrade to version 2.3.17 or 3.3.5, which fix this issue. Customers who host their CMS with Xibo Signage have already received an upgrade or patch to resolve this issue regardless of the CMS version that they are running.
Affected vendor
Xibosignage
Affected product
Xibo
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness type (CWE)
Published
2023-05-30

Risk analysis

Based on its CVSS vector, this vulnerability is exploitable over the network, low attack complexity, requiring low privileges, no user interaction. Successful exploitation leads to high impact to confidentiality, high impact to integrity, high impact to availability.

Its EPSS score of 7.1% reflects a lower probability of exploitation activity in the wild over the next 30 days, placing it above 94% of all scored CVEs.

Check your external exposure to CVE-2023-33177

  • Confirm whether Xibosignage Xibo is running on any internet-facing host or subdomain.
  • Match discovered service fingerprints against the version affected by CVE-2023-33177.
  • Prioritise remediation if the asset is public, business-critical, or near authentication/payment flows.

How ThreatPort helps with CVE-2023-33177

ThreatPort's external attack surface scanner checks your internet-facing assets — agentlessly, from the outside in — for the exposed services and versions that CVE-2023-33177 affects, then prioritises the finding by real risk using CISA KEV and FIRST.org EPSS.

Run a free external exposure scan

Are you exposed to CVE-2023-33177?

Run an instant, non-intrusive external scan to check your attack surface for CVE-2023-33177.

Start free scan

No credit card. Agentless.