Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pqcf-v8v5-jmcg

Опубликовано: 10 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

Zip slip in Microweber

A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload a maliciously constructed ZIP file with file paths including relative paths (i.e., ../../), move this file into the backup directory, and execute a restore on this file.

Пакеты

Наименование

microweber/microweber

composer
Затронутые версииВерсия исправления

< 1.2.3

1.2.3

EPSS

Процентиль: 94%
0.1411
Средний

7.2 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.2
nvd
почти 5 лет назад

A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload a maliciously constructed ZIP file with file paths including relative paths (i.e., ../../), move this file into the backup directory, and execute a restore on this file.

EPSS

Процентиль: 94%
0.1411
Средний

7.2 High

CVSS3

Дефекты

CWE-22