CVE-2020-13405: Infoleak
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.
Other sources
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-13405.
What is the severity rating of CVE-2020-13405?
CVE-2020-13405 has a severity rating of 7.5 (high).
How does CVE-2020-13405 impact Microweber before version 1.1.20?
CVE-2020-13405 allows an unauthenticated user to disclose the users database via a `/modules/ POST` request in Microweber before version 1.1.20.
How can I fix CVE-2020-13405?
To fix CVE-2020-13405, update to version 1.1.20 of Microweber.
Where can I find more information about CVE-2020-13405?
More information about CVE-2020-13405 can be found at the following links: [link1](https://nvd.nist.gov/vuln/detail/CVE-2020-13405), [link2](https://github.com/microweber/microweber/commit/269320e0e0e06a1785e1a1556da769a34280b7e6), [link3](https://rhinosecuritylabs.com/research/microweber-database-disclosure/).