Description
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://gist.github.com/virendratiwari03/0918aaba97eba31666630996ab3aeec3
Third Party Advisory x_refsource_misc
https://gist.github.com/virendratiwari03/800f96271f22c0c2f5aea126c7f1f170
Scores
CVSS v3
9.8
EPSS
0.0043
EPSS Percentile
62.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (1)
microweber/microweber
1.1.18
Published
Nov 09, 2020
Tracked Since
Feb 18, 2026