PT-2022-13387 · Unknown · Microweber

Published

2022-02-23

·

Updated

2022-03-02

·

CVE-2022-0721

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions microweber versions prior to 1.3
Description The issue concerns the insertion of sensitive information into debugging code in the microweber GitHub repository. When the server is run in debug mode, it may expose sensitive information about the server and user.
Recommendations For versions prior to 1.3, update to version 1.3 or later to resolve the issue. As a temporary workaround, consider disabling debug mode until a patch is available. Restrict access to sensitive information to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0721
GHSA-MJVC-J6RV-9XJ8

Affected Products

Microweber