Skip to content

Instantly share code, notes, and snippets.

@grozdniyandy
Created November 22, 2023 14:07
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save grozdniyandy/1847ad48126d6bba39bdeb49114bc300 to your computer and use it in GitHub Desktop.
Save grozdniyandy/1847ad48126d6bba39bdeb49114bc300 to your computer and use it in GitHub Desktop.
CVE-2023-48122
> [Description]
> An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote
> attacker to obtain sensitive information via the HTTP GET method.
> ------------------------------------------
> [VulnerabilityType Other]
> Use of GET Request Method With Sensitive Query Strings
> ------------------------------------------
> [Vendor of Product]
> microweber
> ------------------------------------------
> [Affected Product Code Base]
> microweber - 2.0.1
> ------------------------------------------
> [Attack Type]
> Remote
> ------------------------------------------
> [CVE Impact Other]
> Account Takeover
> ------------------------------------------
> [Reference]
> https://github.com/microweber/microweber/issues/1042
> ------------------------------------------
> [Discoverer]
> https://github.com/grozdniyandy
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment