ZeroHour

CVE-2021-36461

PoC
CVSS 3.1
8.8 high
EPSS
<1%p58
Published
()
Modified
Description

An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini.

Vendors
microweber
Products
microweber
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.