microweber/microweber prior to 1.3.3 is vulnerable to command injection in the “first name” field. This allows for server-side template injection, which can lead to arbitrary code execution.
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1877
ht…