PT-2021-11504 · Unknown · Microweber

Sl1Nki

·

Published

2021-02-15

·

Updated

2022-02-10

·

CVE-2020-28337

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Microweber versions 1.1.20 and earlier
Description: A directory traversal issue in the Utils/Unzip module allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit this issue, an attacker must have administrative user credentials, upload a maliciously constructed ZIP file with relative paths (e.g., ../../), move this file into the backup directory, and execute a restore on this file.
Recommendations: For Microweber versions 1.1.20 and earlier, update to a version later than 1.1.20 to resolve the issue. As a temporary workaround, consider restricting access to the backup restore feature and the Utils/Unzip module to minimize the risk of exploitation. Avoid using the backup restore feature with untrusted ZIP files until the issue is resolved.

Exploit

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-28337
GHSA-PQCF-V8V5-JMCG

Affected Products

Microweber