CVE-2023-27168

Executive Summary

CVE-2023-27168 exposes Xpand IT Write‑back Manager v2.3.1 to arbitrary file upload. An attacker can upload a malicious JSP, which the server executes, enabling remote code execution. The flaw is not yet in CISA KEV. Immediate patching or disabling upload functionality is recommended.


Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2024-01-19T14:15:12.247 - Last Modified: 2026-09-16T20:17:19.743

Original Description: An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.

"I never think of the future. It comes soon enough."

— Albert Einstein
Source: NVD