Vulnerabilities
Vulnerable Software
Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.
CVSS Score
6.5
EPSS Score
0.003
Published
2022-01-20
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVSS Score
7.2
EPSS Score
0.002
Published
2022-01-20
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload a maliciously constructed ZIP file with file paths including relative paths (i.e., ../../), move this file into the backup directory, and execute a restore on this file.
CVSS Score
7.2
EPSS Score
0.141
Published
2021-02-15


Contact Us

Shodan ® - All rights reserved