Vulnerability Description
Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extension (used with the Add Image option on the Edit User screen) corresponds to an image file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microweber | Microweber | 1.1.18 |
Related Weaknesses (CWE)
References
- https://gist.github.com/virendratiwari03/0af29841fdf27207eb3abc8f28d326f3ExploitThird Party Advisory
- https://gist.github.com/virendratiwari03/0af29841fdf27207eb3abc8f28d326f3ExploitThird Party Advisory
FAQ
What is CVE-2020-13241?
CVE-2020-13241 is a vulnerability with a CVSS score of 7.8 (HIGH). Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extension (used with the Add Image option on the Edit User scre...
How severe is CVE-2020-13241?
CVE-2020-13241 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-13241?
Check the references section above for vendor advisories and patch information. Affected products include: Microweber Microweber.