CVE-2025-34076 is an authenticated local file inclusion vulnerability affecting Microweber CMS versions up to 1.2.11. Authenticated users can exploit flaws in the backup management API's upload and download endpoints to read arbitrary files from the server's filesystem, and potentially relocate or delete them. With a CVSS score of 7.2 (HIGH), this vulnerability allows for high impact to confidentiality, integrity, and availability, requiring high privileges but low attack complexity. While not yet in CISA's KEV catalog, a Metasploit module exists, and there is significant community discussion, indicating a high likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.2.11CPE matchmatch criteria | cpe:2.3:a:microweber:microweber:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.