PT-2026-64188 · Unknown · Microweber Cms
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Microweber CMS versions prior to 2.0.21
Description
A path traversal issue exists in the static file controller. Unauthenticated remote attackers can read arbitrary files, including system files and environment configuration files containing credentials, by sending a single HTTP GET request. This is possible because the
normalize path() function fails to properly strip directory traversal sequences provided in the path query parameter.Recommendations
Update Microweber CMS to version 2.0.21 or later.
Exploit
Fix
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Microweber Cms