CVE-2022-0762: Incorrect Authorization in microweber/microweber
Published Feb 26, 2022
·Updated
Exposure of Resource to Wrong Sphere in microweber prior to 1.3 allows users to add deleted products to a cart and buy it.
Other sources
Incorrect Authorization in GitHub repository microweber/microweber prior to 1.3.
— MITRE
Affected Software
2 affected componentsFixes available
composer/microweber/microweber<1.3.0
1.3.0
Microweber Microweber<1.3
Remediation
Event History
Feb 26, 2022
CVE Published
via MITRE·09:35 AM
Data Sourced
via MITRE·09:35 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 27, 2022
Advisory Published
12:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2022-0762?
CVE-2022-0762 is classified as a medium severity vulnerability due to improper authorization issues.
2
How do I fix CVE-2022-0762?
To fix CVE-2022-0762, upgrade to Microweber version 1.3.0 or later.
3
What kind of vulnerability is CVE-2022-0762?
CVE-2022-0762 is an authorization vulnerability that allows users to purchase deleted products.
4
In which versions is CVE-2022-0762 present?
CVE-2022-0762 affects Microweber versions prior to 1.3.
5
Who is affected by CVE-2022-0762?
Users of Microweber who have versions before 1.3 are impacted by CVE-2022-0762.