CVE-2021-36461

HIGH

Microweber 1.1.3 - Arbitrary File Upload via Settings Upload Picture

Title source: llm
STIX 2.1

Description

An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini.

References (1)

Core 1
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/microweber/microweber/issues/751

Scores

CVSS v3 8.8
EPSS 0.0079
EPSS Percentile 51.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
microweber/microweber 1.1.3
Published Jul 15, 2022
Tracked Since Feb 18, 2026