CVE-2022-33012: High severity microweber whmcs vulnerability
Published Nov 22, 2022
·Updated
Microweber 1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.
Other sources
Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.
Affected Software
2 affected components
Microweber Microweber=1.2.15
composer/microweber/microweber<=1.2.15
Event History
Nov 22, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:30 PM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-33012.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Microweber v1.2.15 Account Takeover via Host Header Injection'.
3
What is the severity of CVE-2022-33012?
The severity of CVE-2022-33012 is high with a CVSS score of 8.8.
4
How can attackers exploit this vulnerability?
Attackers can exploit this vulnerability by performing an account takeover through a host header injection attack.
5
How can I fix this vulnerability?
To fix this vulnerability, it is recommended to update Microweber to version 1.2.16 or later.