Vulnerability record · CVE-2022-0557 · published 11 February 2022
CVE-2022-0557: Microweber OS command injection before 1.2.11
Microweber · Microweber
Microweber versions prior to 1.2.11 contain an OS command injection flaw (CWE-78) that lets an attacker run operating system commands through the application. The record does not describe the exact vulnerable parameter or code path, but public exploit references exist, so the flaw is reachable in practice.
Description
OS Command Injection in Packagist microweber/microweber prior to 1.2.11.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityNetwork-reachable command injection with public exploit code and a high EPSS score, though exploitation requires an authenticated high-privilege account.
What it is
Microweber versions prior to 1.2.11 contain an OS command injection flaw (CWE-78) that lets an attacker run operating system commands through the application. The record does not describe the exact vulnerable parameter or code path, but public exploit references exist, so the flaw is reachable in practice.
Impact
An attacker who can reach the vulnerable function gains arbitrary command execution with the privileges of the web server process, leading to full compromise of the host and any data it can access.
Attack surface
The CVSS vector is network-reachable (AV:N) with no user interaction (UI:N), but requires high privileges (PR:H), meaning the attacker needs an authenticated administrative-level account. The description does not identify the specific endpoint or parameter involved.
Exploitation
CVE-2022-0557 is not listed in CISA KEV, but EPSS is high at 0.512 (98.9th percentile) and multiple references are tagged Exploit, including Packet Storm and Exploit-DB entries, indicating public exploit code is available.
What to do
- Upgrade Microweber to 1.2.11 or later, applying the vendor patch commit 0a7e5f1d81de884861ca677ee1aaac31f188d632.
- Restrict administrative access to the Microweber instance to trusted networks or VPN, since exploitation requires high privileges.
- Run the web server and PHP process under a low-privilege account with no shell access and minimal filesystem permissions.
- Monitor and alert on unexpected child processes spawned by the web server (for example shell, curl, wget, or netcat).
- If patching is delayed, consider a WAF rule blocking command-injection patterns in requests to Microweber admin endpoints.
Detection
- Search web server and application logs for requests to Microweber admin endpoints containing shell metacharacters (;, |, &&, $(), backticks).
- Monitor process creation on the host for shell or utility processes whose parent is the web server or PHP-FPM.
- Review file upload and write activity in the Microweber webroot for unexpected PHP or shell files, consistent with the referenced shell upload exploit.
- Correlate authentication logs for admin logins from unusual source IPs with subsequent command execution or file changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/166077/Microweber-1.2.11-Shell-Upload.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/microweber/microweber/commit/0a7e5f1d81de884861ca677ee1aaac31f188d632 | PatchThird Party Advisory |
| https://huntr.dev/bounties/660c89af-2de5-41bc-aada-9e4e78142db8 | ExploitPatchThird Party Advisory |
| https://www.exploit-db.com/exploits/50768 | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/166077/Microweber-1.2.11-Shell-Upload.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/microweber/microweber/commit/0a7e5f1d81de884861ca677ee1aaac31f188d632 | PatchThird Party Advisory |
| https://huntr.dev/bounties/660c89af-2de5-41bc-aada-9e4e78142db8 | ExploitPatchThird Party Advisory |
| https://www.exploit-db.com/exploits/50768 | ExploitThird Party Advisory |
Track CVE-2022-0557 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-0557), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.