CVE-2020-23138

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
09/11/2020
Last modified:
20/11/2020

Description

An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microweber:microweber:1.1.18:*:*:*:*:*:*:*