CVE-2021-36461: Malicious File Upload
An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-36461?
CVE-2021-36461 is an Arbitrary File Upload vulnerability in Microweber 1.1.3 that allows attackers to getshell by maliciously uploading pictures via the Settings Upload Picture section.
How does CVE-2021-36461 work?
CVE-2021-36461 works by exploiting the file upload functionality in Microweber 1.1.3, allowing attackers to upload pictures with malicious code, user.ini.
What is the severity of CVE-2021-36461?
CVE-2021-36461 has a severity score of 8.8 (high).
How can I fix CVE-2021-36461?
To fix CVE-2021-36461, update your Microweber software to version 1.1.4 or later.
Where can I find more information about CVE-2021-36461?
More information about CVE-2021-36461 can be found at the following reference link: [GitHub - Microweber issue #751](https://github.com/microweber/microweber/issues/751)