Loading HuntDB...

GHSA-582p-2fpg-x226

GitHub Security Advisory

Microweber vulnerable to command injection

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

microweber/microweber prior to 1.3.3 is vulnerable to command injection in the "first name" field. This allows for server-side template injection, which can lead to arbitrary code execution.

Affected Packages

Packagist microweber/microweber
Affected versions: 0 (fixed in 1.3.3)

Related CVEs

Key Information

GHSA ID
GHSA-582p-2fpg-x226
Published
April 5, 2023 6:30 PM
Last Modified
April 6, 2023 4:37 PM
CVSS Score
5.0 /10
Primary Ecosystem
Packagist
Primary Package
microweber/microweber
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 4, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.