Vulnerabilities
Vulnerable Software
Microweber:  >> Microweber  Security Vulnerabilities
Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.
CVSS Score
6.5
EPSS Score
0.003
Published
2022-01-20
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVSS Score
7.2
EPSS Score
0.002
Published
2022-01-20
Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by Inserting code in the request form.
CVSS Score
6.1
EPSS Score
0.008
Published
2021-10-19
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload a maliciously constructed ZIP file with file paths including relative paths (i.e., ../../), move this file into the backup directory, and execute a restore on this file.
CVSS Score
7.2
EPSS Score
0.141
Published
2021-02-15
Microweber v1.1.18 is affected by no session expiry after log-out.
CVSS Score
5.5
EPSS Score
0.001
Published
2020-11-09
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.
CVSS Score
9.8
EPSS Score
0.004
Published
2020-11-09
Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise.
CVSS Score
5.5
EPSS Score
0.001
Published
2020-11-09
Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session does not expire and remains active.
CVSS Score
8.1
EPSS Score
0.003
Published
2020-11-09
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.
CVSS Score
7.5
EPSS Score
0.243
Published
2020-07-16
Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extension (used with the Add Image option on the Edit User screen) corresponds to an image file.
CVSS Score
7.8
EPSS Score
0.0
Published
2020-05-20


Contact Us

Shodan ® - All rights reserved