Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12.
References
Link | Resource |
---|---|
https://github.com/microweber/microweber/commit/867bdda1b4660b0795ad7f87ab5abe9e44b2b318 | Patch Third Party Advisory |
https://huntr.dev/bounties/e368be37-1cb4-4292-8d48-07132725f622 | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-03-11 10:15
Updated : 2022-03-18 06:48
NVD link : CVE-2022-0921
Mitre link : CVE-2022-0921
JSON object : View
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
Products Affected
microweber
- microweber