Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2020-23136

Disclosure Date: November 09, 2020 (last updated February 22, 2025)
Microweber v1.1.18 is affected by no session expiry after log-out.
Attacker Value
Unknown

CVE-2020-23139

Disclosure Date: November 09, 2020 (last updated February 22, 2025)
Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise.
Attacker Value
Unknown

CVE-2020-23138

Disclosure Date: November 09, 2020 (last updated February 22, 2025)
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.
Attacker Value
Unknown

CVE-2020-23140

Disclosure Date: November 09, 2020 (last updated February 22, 2025)
Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session does not expire and remains active.
Attacker Value
Unknown

CVE-2020-13241

Disclosure Date: May 20, 2020 (last updated February 21, 2025)
Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extension (used with the Add Image option on the Edit User screen) corresponds to an image file.