PT-2022-21645 · Unknown · Microweber

Phoenix

·

Published

2022-11-22

·

Updated

2022-11-28

·

CVE-2022-33012

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microweber version 1.2.15
Description The issue allows attackers to perform an account takeover via a host header injection attack. This enables unauthorized access to user accounts, potentially leading to data breaches or other malicious activities.
Recommendations For Microweber version 1.2.15, update to a newer version that contains a fix for this issue. As a temporary workaround, consider restricting access to sensitive account settings to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-33012
GHSA-RP7F-FHM8-9HPF

Affected Products

Microweber