← volver
CVE-2020-28337

CVE-2020-28337

28Vexday Risk Score

Sin señal de explotación. Ella tiene prueba de concepto pública.

ssvc Attendepss 17%
de la publicación al arma84 días
Publicada en NVD15 feb
1ª PoC+84d
probabilidad de explotación
17%top 3% de las CVE
explotación observada
noninguna fuente lo reporta
2 exploit(s) público(s)
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload a maliciously constructed ZIP file with file paths including relative paths (i.e., ../../), move this file into the backup directory, and execute a restore on this file.
Productos afectados
n/a · n/a
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.