First published: Tue Nov 22 2022(Updated: )
Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microweber Microweber | =1.2.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-33012.
The title of this vulnerability is 'Microweber v1.2.15 Account Takeover via Host Header Injection'.
The severity of CVE-2022-33012 is high with a CVSS score of 8.8.
Attackers can exploit this vulnerability by performing an account takeover through a host header injection attack.
To fix this vulnerability, it is recommended to update Microweber to version 1.2.16 or later.