S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0660 Scanner

CVE-2022-0660 scanner - Information Disclosure vulnerability in microweber/microweber

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0660
7.5
CVSScritical
Exploitable remotely over the internet · no authentication required.

Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
microweber/microweberby microweber
AFFECTED< 1.2.11SAFE ✓≥ 1.2.11
Updated Aug 22, 2026View on NVD →
Detail

Microweber/Microweber is a free open-source content management system (CMS) that offers an intuitive interface and customizable design for creating websites, blogs, and online stores. It is a popular choice for web developers and businesses of all sizes due to its user-friendly interface and advanced features.

Recently, a serious vulnerability was detected in Microweber/Microweber prior to 1.2.11, identified as CVE-2022-0660. This vulnerability is related to the generation of an error message that contains sensitive information such as the administrator password, which can be accessed by unauthorized users. The error message also exposes technical details such as the system path, PHP version, and other sensitive information.

If exploited, this vulnerability can lead to serious security issues for websites built on Microweber/Microweber. The exposed password can give hackers access to the backend of the website, allowing them to steal sensitive data such as customer information, email accounts, or credit card details. In addition, the system path and PHP version can be exploited to conduct further attacks on the website.

In conclusion, it is crucial to stay aware of vulnerabilities and security threats to protect your digital assets. Thanks to the pro features of s4e.io platform, readers can easily and quickly identify and resolve vulnerabilities before they cause any significant damage. By following the recommended precautions and utilizing reliable security tools, users can ensure the safety and security of their websites and online stores.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of Microweber/Microweber should take the following precautions:

  • Update to the latest version of Microweber/Microweber 1.2.11 or later to address the vulnerability.
  • Disable error reporting in the configuration file to prevent sensitive information from being exposed in error messages.
  • Ensure that all passwords are strong and unique and change them frequently.
  • Regularly backup website files and database to prevent data loss in the event of a breach.
  • Regularly scan the website for vulnerabilities using security tools.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.