CVE-2022-0666: falha de alta gravidade em microweber/microweber
CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweber
Publicada em · Atualizada em
48Vexday Risk Score
Corrija em breve. Ela tem exploit funcional público.
ssvc Attendcvss 7.6epss 44%
probabilidade de exploração
44%top 1% das CVEs
exploração observada
nãonenhuma fonte reporta
CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in Packagist microweber/microweber prior to 1.2.11.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Produtos afetados
microweber · microweber/microweberCVEs relacionadas — microweber/microweber
No mesmo produto, das mais perigosas para as menos.
CVE-2022-0557HIGHOS Command Injection in microweber/microweberEPSS 51.2%CVE-2022-4732MEDIUMUnrestricted Upload of File with Dangerous Type in microweber/microweberEPSS 38.2%CVE-2022-0281HIGHExposure of Sensitive Information to an Unauthorized Actor in microweber/microweberEPSS 10.5%CVE-2022-1631MEDIUMUsers Account Pre-Takeover or Users Account Takeover. in microweber/microweberEPSS 8.8%CVE-2022-0660CRITICALGeneration of Error Message Containing Sensitive Information in microweber/microweberEPSS 6.9%CVE-2022-0378HIGHCross-site Scripting (XSS) - Reflected in microweber/microweberEPSS 3.9%