CVE-2022-0660: Generation of Error Message Containing Sensitive Information in microweber/microweber
Published Feb 18, 2022
·Updated
Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.
Affected Software
1 affected component
Microweber Microweber<1.2.11
Remediation
Event History
Feb 18, 2022
CVE Published
via MITRE·11:10 AM
Data Sourced
via MITRE·11:10 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-0660?
CVE-2022-0660 is rated as a medium severity vulnerability due to the potential exposure of sensitive information.
2
How do I fix CVE-2022-0660?
To fix CVE-2022-0660, upgrade the microweber software to version 1.2.11 or later.
3
What type of information is exposed in CVE-2022-0660?
CVE-2022-0660 may generate error messages that contain sensitive information about the application's environment.
4
Which versions of microweber are affected by CVE-2022-0660?
CVE-2022-0660 affects all versions of microweber prior to 1.2.11.
5
Is CVE-2022-0660 a remote or local vulnerability?
CVE-2022-0660 can be exploited by remote attackers who can trigger error messages revealing sensitive information.