CVE-2020-13241: Malicious File Upload
Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/loadmodule:users#edit-user=1 does not verify that the file extension (used with the Add Image option on the Edit User screen) corresponds to an image file.
Other sources
Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/loadmodule:users#edit-user=1 does not verify that the file extension (used with the Add Image option on the Edit User screen) corresponds to an image file.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of Microweber?
The vulnerability ID of Microweber is CVE-2020-13241.
What is the severity level of CVE-2020-13241?
The severity level of CVE-2020-13241 is high.
What is the affected software version of CVE-2020-13241?
The affected software version of CVE-2020-13241 is Microweber 1.1.18.
What is the main cause of CVE-2020-13241 vulnerability?
The main cause of CVE-2020-13241 vulnerability is the lack of verification of file extension for image uploads.
How can I fix CVE-2020-13241 vulnerability in Microweber 1.1.18?
To fix CVE-2020-13241 vulnerability, ensure that file extensions are properly verified for image uploads in Microweber 1.1.18.