CVE-2020-23138
09.11.2020, 18:15
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.Enginsight
Vendor | Product | Version |
---|---|---|
microweber | microweber | 1.1.18 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References