CVE-2022-0666: CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweber
Published Feb 18, 2022
·Updated
CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in Packagist microweber/microweber prior to 1.2.11.
Affected Software
1 affected component
Microweber Microweber<1.2.11
Remediation
Event History
Feb 18, 2022
CVE Published
via MITRE·02:55 PM
Data Sourced
via MITRE·02:55 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-0666?
CVE-2022-0666 is classified as a medium severity vulnerability.
2
How do I fix CVE-2022-0666?
To fix CVE-2022-0666, update Microweber to version 1.2.11 or later.
3
What kind of vulnerability is CVE-2022-0666?
CVE-2022-0666 is a CRLF Injection vulnerability that can lead to stack trace exposure.
4
What software versions are affected by CVE-2022-0666?
CVE-2022-0666 affects all versions of Microweber before 1.2.11.
5
What is the impact of CVE-2022-0666?
The impact of CVE-2022-0666 includes potential exposure of stack traces, which can reveal sensitive information.