Fiche vulnérabilité
CVE-2021-36461 : faille élevée microweber microweber (CVSS 8.8)
Description
An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini.
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 15 juil. 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- microweber microweber