CVE-2022-0921

MEDIUM6.7EPSS 4.6%

Unrestricted Upload of File with Dangerous Type in Microweber

Published: 3/12/2022Modified: 11/8/2023
Also known as:GHSA-j878-43hm-8gr5

Description

In Microweber prior to 1.2.12, a malicious actor may abuse the Backup/Restore feature to achieve Remote Code Execution.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.7CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References (4)