CVE-2023-48122: Infoleak
Published Dec 8, 2023
·Updated
An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method.
Other sources
An issue present in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method.
Affected Software
2 affected componentsFixes available
composer/microweber/microweber>=2.0.1<2.0.4
2.0.4
Microweber Microweber>=2.0.1<2.0.4
Event History
Dec 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
06:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-48122?
CVE-2023-48122 has a medium severity rating due to the potential exposure of sensitive information.
2
How do I fix CVE-2023-48122?
To fix CVE-2023-48122, upgrade your Microweber installation to version 2.0.4 or later.
3
What versions of Microweber are affected by CVE-2023-48122?
CVE-2023-48122 affects Microweber version 2.0.1 and earlier.
4
Can CVE-2023-48122 be exploited remotely?
Yes, CVE-2023-48122 can be exploited remotely by an attacker using the HTTP GET method.
5
What kind of sensitive information can be exposed by CVE-2023-48122?
CVE-2023-48122 can expose various types of sensitive data depending on the application context.