← Vulnerability feed

Vulnerability record · CVE-2022-0557 · published 11 February 2022

CVE-2022-0557: Microweber OS command injection before 1.2.11

Microweber · Microweber

Microweber versions prior to 1.2.11 contain an OS command injection flaw (CWE-78) that lets an attacker run operating system commands through the application. The record does not describe the exact vulnerable parameter or code path, but public exploit references exist, so the flaw is reachable in practice.

7.2 CVSS 3.1 High EPSS 51% · top 1.1% CWE-78 · OS command injection
7.2CVSS 3.1 base score, v2 9.0
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

OS Command Injection in Packagist microweber/microweber prior to 1.2.11.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityNetwork-reachable command injection with public exploit code and a high EPSS score, though exploitation requires an authenticated high-privilege account.

What it is

Microweber versions prior to 1.2.11 contain an OS command injection flaw (CWE-78) that lets an attacker run operating system commands through the application. The record does not describe the exact vulnerable parameter or code path, but public exploit references exist, so the flaw is reachable in practice.

Impact

An attacker who can reach the vulnerable function gains arbitrary command execution with the privileges of the web server process, leading to full compromise of the host and any data it can access.

Attack surface

The CVSS vector is network-reachable (AV:N) with no user interaction (UI:N), but requires high privileges (PR:H), meaning the attacker needs an authenticated administrative-level account. The description does not identify the specific endpoint or parameter involved.

Exploitation

CVE-2022-0557 is not listed in CISA KEV, but EPSS is high at 0.512 (98.9th percentile) and multiple references are tagged Exploit, including Packet Storm and Exploit-DB entries, indicating public exploit code is available.

What to do

  • Upgrade Microweber to 1.2.11 or later, applying the vendor patch commit 0a7e5f1d81de884861ca677ee1aaac31f188d632.
  • Restrict administrative access to the Microweber instance to trusted networks or VPN, since exploitation requires high privileges.
  • Run the web server and PHP process under a low-privilege account with no shell access and minimal filesystem permissions.
  • Monitor and alert on unexpected child processes spawned by the web server (for example shell, curl, wget, or netcat).
  • If patching is delayed, consider a WAF rule blocking command-injection patterns in requests to Microweber admin endpoints.

Detection

  • Search web server and application logs for requests to Microweber admin endpoints containing shell metacharacters (;, |, &&, $(), backticks).
  • Monitor process creation on the host for shell or utility processes whose parent is the web server or PHP-FPM.
  • Review file upload and write activity in the Microweber webroot for unexpected PHP or shell files, consistent with the referenced shell upload exploit.
  • Correlate authentication logs for admin logins from unusual source IPs with subsequent command execution or file changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-0557 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-1877Microweber command injection vulnerabilityCommand Injection in GitHub repository microweber/microweber prior to 1.3.3.EPSS 1.8%9.8CVE-2022-2368Microweber authentication bypass by spoofing vulnerabilityAuthentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.EPSS 1.2%9.8CVE-2022-0895Microweber vulnerabilityStatic Code Injection in GitHub repository microweber/microweber prior to 1.3.EPSS 1.7%9.8CVE-2020-23138Microweber unrestricted file upload vulnerabilityAn unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extensio…EPSS 1.3%8.8CVE-2023-49052Microweber unrestricted file upload vulnerabilityFile Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function i…EPSS 2.4%8.8CVE-2023-2240Microweber improper privilege management vulnerabilityImproper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4.EPSS 0.71%8.8CVE-2022-33012Microweber injection vulnerabilityMicroweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.EPSS 1.4%8.8CVE-2021-36461Microweber unrestricted file upload vulnerabilityAn Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by upload…EPSS 0.92%

Source: NIST National Vulnerability Database (record CVE-2022-0557), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.