Critical severity9.8NVD Advisory· Published Nov 9, 2020· Updated Jun 17, 2026
CVE-2020-23138
CVE-2020-23138
Description
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Microweber/Microweberdescription
- Range: = 1.1.18
Patches
Vulnerability mechanics
References
2- gist.github.com/virendratiwari03/0918aaba97eba31666630996ab3aeec3nvdThird Party Advisory
- gist.github.com/virendratiwari03/800f96271f22c0c2f5aea126c7f1f170nvdThird Party Advisory
News mentions
0No linked articles in our index yet.