8.8

CVE-2022-0721

Exploit

Insertion of Sensitive Information Into Debugging Code in microweber/microweber

Insertion of Sensitive Information Into Debugging Code in GitHub repository microweber/microweber prior to 1.3.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicroweberMicroweber Version < 1.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.38% 0.685
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
security@huntr.dev 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-215 Insertion of Sensitive Information Into Debugging Code

The product inserts sensitive information into debugging code, which could expose this information if the debugging code is not disabled in production.

https://github.com/microweber/microweber/commit/b12e1a490c79460bff019f34b2e17112249b16ec
Patch
Third Party Advisory
https://huntr.dev/bounties/ae267d39-9750-4c69-be8b-4f915da089fb
Patch
Third Party Advisory
Exploit