GHSA-j64v-xh5w-8hqj · Severity: medium · Ecosystem: composer — Microweber CMS API has authenticated local file inclusion vulnerability
An authenticated local file inclusion vulnerability exists in Microweber CMS versions <= 1.2.11 through misuse of the backup management API. Authenticated users can abuse the /api/BackupV2/upload and /api/BackupV2/download endpoints to read arbitrary files from the underlying filesystem. By specifying an absolute file path in the src parameter of the upload request, the server may relocate or delete the target file depending on the web service user’s privileges. The corresponding download endpoint can then be used to retrieve the file contents, effectively enabling local file disclosure. This behavior stems from insufficient validation of user-supplied paths and inadequate restrictions on file access and backup logic.
Conclusion & alert: CVE-2025-34076 is rated High Exploit Risk (78/100): CVSS Medium severity, with high exploitation likelihood (EPSS 48.76%, 98th percentile). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +4.38% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-10 | 44.38% | 48.76% | +4.38% |
| 2 | 2026-04-28 | 24.57% | 44.38% | +19.81% |
| 3 | 2026-03-18 | — | 24.57% | — |
Full EPSS history (14 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.1 | 4.0 | MEDIUM |
|
— | — | [email protected] |
| 7.2 | 3.1 | HIGH |
|
1.2 | 5.9 | [email protected] |
GHSA-j64v-xh5w-8hqj · Severity: medium · Ecosystem: composer — Microweber CMS API has authenticated local file inclusion vulnerability
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| microweber | microweber | <= 1.2.11 | cpe:2.3:a:microweber:microweber:*:*:*:*:*:*:*:* |