Impact
This vulnerability is an arbitrary file upload flaw caused by insufficient validation in the Microweber administration panel’s upload forms. An attacker who can authenticate to the admin area can upload any file type to the server. Test files such as the EICAR test file have been used to demonstrate that upload leads to remote code execution, potentially allowing full compromise of the system.
Affected Systems
The affected product is the Microweber administration panel, specifically version 2.0.19 as identified by the CPE string.
Risk and Exploitability
The CVSS score of 8.4 signifies a high severity level. The exploit probability, according to the EPSS score, is not currently available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires authenticated access to the admin interface, after which the attacker can upload a malicious file that the server will execute, resulting in remote code execution.
OpenCVE Enrichment