Microweber CMS <= 2.0.20 contains a path traversal vulnerability caused by failure to normalize path query parameter in static file controller, letting unauthenticated remote attackers read arbitrary files.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view