First published: Thu Jul 16 2020(Updated: )
`userfiles/modules/users/controller/controller.php` in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a `/modules/ POST` request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/microweber/microweber | <1.1.20 | 1.1.20 |
Microweber WHMCS | <1.1.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-13405.
CVE-2020-13405 has a severity rating of 7.5 (high).
CVE-2020-13405 allows an unauthenticated user to disclose the users database via a `/modules/ POST` request in Microweber before version 1.1.20.
To fix CVE-2020-13405, update to version 1.1.20 of Microweber.
More information about CVE-2020-13405 can be found at the following links: [link1](https://nvd.nist.gov/vuln/detail/CVE-2020-13405), [link2](https://github.com/microweber/microweber/commit/269320e0e0e06a1785e1a1556da769a34280b7e6), [link3](https://rhinosecuritylabs.com/research/microweber-database-disclosure/).