CVE-2020-23139

MEDIUM

Microweber 1.1.18 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise.

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0031
EPSS Percentile 22.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-287
Status published
Products (1)
microweber/microweber 1.1.18
Published Nov 09, 2020
Tracked Since Feb 18, 2026