packetstormsecurity.com
http://packetstormsecurity.com/files/162514/Microweber-CMS-1.1.20-Remote-Code-Execution.html CVE-2020-28337
HIGH
Zip slip in Microweber
Record summary
CVE-2020-28337 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit.
Description
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload a maliciously constructed ZIP file with file paths including relative paths (i.e., ../../), move this file into the backup directory, and execute a restore on this file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
microweber/microweberBrowse Packagist / microweber/microweber | GitHub Advisory | Before 1.2.3 · Fixed in 1.2.3 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBMicroweber CMS 1.1.20 - Remote Code Execution (Authenticated)ExploitDB exploitby sl1nkiNot analyzed1 file
References
5github.com
https://github.com/microweber/microweber/commit/777ee9c3e7519eb3672c79ac41066175b2001b50 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-28337 sl1nki.page
https://sl1nki.page/advisories/CVE-2020-28337 sl1nki.page
https://sl1nki.page/blog/2021/02/01/microweber-zip-slip