Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users to upload files to the server without restrictions. An attacker could exploit this flaw to execute malicious code remotely (demonstrated by uploading the EICAR test file), which could result in the system being completely compromised.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
There is no reported solution at this time.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users to upload files to the server without restrictions. An attacker could exploit this flaw to execute malicious code remotely (demonstrated by uploading the EICAR test file), which could result in the system being completely compromised. | |
| Title | Multiple vulnerabilities in the Microweber administration panel | |
| First Time appeared |
Microweber
Microweber administration Panel |
|
| Weaknesses | CWE-434 | |
| CPEs | cpe:2.3:a:microweber:administration_panel:2.0.19:*:*:*:*:*:*:* | |
| Vendors & Products |
Microweber
Microweber administration Panel |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-09-23T13:46:32.519Z
Reserved: 2026-04-06T12:33:58.454Z
Link: CVE-2026-5695
No data.
Status : Received
Published: 2026-09-23T11:17:10.590
Modified: 2026-09-23T11:17:10.590
Link: CVE-2026-5695
No data.
OpenCVE Enrichment
No data.
Weaknesses