Vulnerabilities
Vulnerable Software
Microweber:  >> Microweber  >> 1.0.7  Security Vulnerabilities
Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.
CVSS Score
7.5
EPSS Score
0.342
Published
2022-01-20
Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.
CVSS Score
6.5
EPSS Score
0.003
Published
2022-01-20
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVSS Score
7.2
EPSS Score
0.002
Published
2022-01-20
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload a maliciously constructed ZIP file with file paths including relative paths (i.e., ../../), move this file into the backup directory, and execute a restore on this file.
CVSS Score
7.2
EPSS Score
0.141
Published
2021-02-15
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.
CVSS Score
7.5
EPSS Score
0.243
Published
2020-07-16
Microweber version <= 1.0.7 contains a Cross Site Scripting (XSS) vulnerability in Admin login form template that can result in Execution of JavaScript code.
CVSS Score
6.1
EPSS Score
0.004
Published
2018-12-20
An issue was discovered in Microweber 1.0.7. There is a CSRF attack (against the admin user) that can add an administrative account via api/save_user.
CVSS Score
8.8
EPSS Score
0.002
Published
2018-09-16


Contact Us

Shodan ® - All rights reserved