CVE-2022-0557
HIGH7.8EPSS 16.9%OS Command Injection in Microweber
發布日:2022/2/12修改日:2023/11/8
描述
Microweber is a content management system with drag and drop. Prior to version 1.2.11, Microweber is vulnerable to OS Command Injection.
受影響套件(1)
- Packagist/microweber/microweberfrom 0, < 1.2.11
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.8 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
參考連結(6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2022-0557
- PATCHhttps://github.com/microweber/microweber
- WEBhttp://packetstormsecurity.com/files/166077/Microweber-1.2.11-Shell-Upload.html
- WEBhttps://github.com/microweber/microweber/commit/0a7e5f1d81de884861ca677ee1aaac31f188d632
- WEBhttps://huntr.dev/bounties/660c89af-2de5-41bc-aada-9e4e78142db8
- WEBhttps://www.exploit-db.com/exploits/50768