CVE-2020-23138
Last modified
CVE-2020-23138 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.. EPSS estimates a 1.30% chance of exploitation in the next 30 days.
Description
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microweber | Microweber | 1.1.18 |
References
- https://gist.github.com/virendratiwari03/0918aaba97eba31666630996ab3aeec3Third Party Advisory
- https://gist.github.com/virendratiwari03/800f96271f22c0c2f5aea126c7f1f170Third Party Advisory
- https://gist.github.com/virendratiwari03/0918aaba97eba31666630996ab3aeec3Third Party Advisory
- https://gist.github.com/virendratiwari03/800f96271f22c0c2f5aea126c7f1f170Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-23138?
How severe is CVE-2020-23138?
How do I fix CVE-2020-23138?
Are you affected by CVE-2020-23138?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
