CVE-2023-23333

There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions...

Basic Information

CVE State
PUBLISHED
Reserved Date
January 11, 2023
Published Date
February 06, 2023
Last Updated
March 26, 2025
Vendor
SolarView
Product
Compact
Description
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.
Tags
php nuclei_scanner

CVSS Scores

CVSS v3.1

9.8 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

Score
94.22% (Percentile: 99.91%) as of 2025-07-29

SSVC Information

Exploitation
poc
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2025-07-07 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-07-08 12:01:10 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

solarview_unauth_rce_cve_2023_23333

Type: metasploit • Created: Unknown

Metasploit module for CVE-2023-23333

emanueldosreis/nmap-CVE-2023-23333-exploit

Type: github • Created: 2023-08-01 16:24:37 UTC • Stars: 2

Nmap NSE script to dump / test Solarwinds CVE-2023-23333 vulnerability

Mr-xn/CVE-2023-23333

Type: github • Created: 2023-06-16 14:33:31 UTC • Stars: 13

SolarView Compact through 6.00 downloader.php commands injection (RCE) nuclei-templates

Timorlover/CVE-2023-23333

Type: github • Created: 2023-02-06 06:20:40 UTC • Stars: 8

There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Detected by Nuclei

  • Detected by Metasploit

  • Added to KEVIntel