CVE-2021-36461

HIGH

Microweber 1.1.3 - RCE

Title source: llm
STIX 2.1

Description

An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini.

References (1)

Core 1
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/microweber/microweber/issues/751

Scores

CVSS v3 8.8
EPSS 0.0035
EPSS Percentile 57.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
microweber/microweber 1.1.3
Published Jul 15, 2022
Tracked Since Feb 18, 2026