CVE-2023-49052: Malicious File Upload
Published Nov 30, 2023
·Updated
File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function in the created forms component.
Affected Software
2 affected components
composer/microweber/microweber<=2.0.4
Microweber Microweber=2.0.4
Remediation
Patch Available
Event History
Nov 30, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
09:30 AM
Frequently Asked Questions
1
What is CVE-2023-49052?
CVE-2023-49052 is a file upload vulnerability in Microweber v.2.0.4 that allows a remote attacker to execute arbitrary code.
2
How does CVE-2023-49052 work?
CVE-2023-49052 works by exploiting a file upload function in the created forms component of Microweber v.2.0.4.
3
How can an attacker exploit CVE-2023-49052?
An attacker can exploit CVE-2023-49052 by crafting a malicious script and uploading it using the vulnerable file upload function in Microweber v.2.0.4.
4
What software versions are affected by CVE-2023-49052?
Microweber v.2.0.4 is the only version affected by CVE-2023-49052.
5
How to fix CVE-2023-49052?
To fix CVE-2023-49052, update Microweber to a version higher than v.2.0.4.