Record summary

CVE-2020-28337 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit.

Description

A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload a maliciously constructed ZIP file with file paths including relative paths (i.e., ../../), move this file into the backup directory, and execute a restore on this file.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 1.2.3 · Fixed in 1.2.3affected

Proofs of concept

1

Catalogued exploits

ExploitDBMicroweber CMS 1.1.20 - Remote Code Execution (Authenticated)ExploitDB exploitby sl1nkiNot analyzed1 file
ExploitDB

PoC details

References

5