CVE-2020-28337
Summary
| CVE | CVE-2020-28337 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-15 20:15:00 UTC |
| Updated | 2022-01-01 18:13:00 UTC |
| Description | A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload a maliciously constructed ZIP file with file paths including relative paths (i.e., ../../), move this file into the backup directory, and execute a restore on this file. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microweber | Microweber | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microweber CMS 1.1.20 Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| update · microweber/microweber@777ee9c · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Microweber - Exploiting a Zip Slip | Sl1nki’s Page | MISC | sl1nki.page | Exploit, Patch, Third Party Advisory |
| CVE-2020-28337 - Microweber v1.1.20 - Zip Slip Directory Traversal | Sl1nki’s Page | MISC | sl1nki.page | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.