
Cloud Vulnerability DB
A community-led vulnerabilities database
An Unrestricted Upload of File with Dangerous Type vulnerability was identified in GitHub repository microweber/microweber versions prior to 1.2.11. The vulnerability was assigned CVE-2022-0912 and was discovered and reported on March 10, 2022 (CVE MITRE).
The vulnerability is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type). The issue involves insufficient validation of file extensions during file uploads, specifically related to PHP file extensions including 'phtml', 'php6', and various other PHP version-specific extensions (GitHub Commit).
This vulnerability could potentially allow attackers to upload malicious PHP files to the affected system, which could lead to remote code execution if the uploaded files are executed by the web server (NVD).
The vulnerability has been patched in version 1.2.11 of the Microweber software. The fix includes updating the dangerous file extensions list to include additional PHP-related extensions such as 'phtml' and 'php6' (GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."