Description
Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users to upload files to the server without restrictions. An attacker could exploit this flaw to execute malicious code remotely (demonstrated by uploading the EICAR test file), which could result in the system being completely compromised.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
There is no reported solution at this time.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users to upload files to the server without restrictions. An attacker could exploit this flaw to execute malicious code remotely (demonstrated by uploading the EICAR test file), which could result in the system being completely compromised. | |
| Title | Multiple vulnerabilities in the Microweber administration panel | |
| First Time appeared |
Microweber
Microweber administration Panel |
|
| Weaknesses | CWE-434 | |
| CPEs | cpe:2.3:a:microweber:administration_panel:2.0.19:*:*:*:*:*:*:* | |
| Vendors & Products |
Microweber
Microweber administration Panel |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-09-23T10:21:26.797Z
Reserved: 2026-04-06T12:33:58.454Z
Link: CVE-2026-5695
No data.
Status : Received
Published: 2026-09-23T11:17:10.590
Modified: 2026-09-23T11:17:10.590
Link: CVE-2026-5695
No data.
OpenCVE Enrichment
No data.
Weaknesses