S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-0597 Scanner

CVE-2022-0597 scanner - Open Redirection vulnerability in Microweber

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0597
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Open Redirect in Packagist microweber/microweber prior to 1.2.11.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
microweber/microweberby microweber
AFFECTED< 1.2.11SAFE ✓≥ 1.2.11
Updated Aug 22, 2026View on NVD →
Detail

Microweber is a drag-and-drop website builder and a powerful content management system (CMS) built on the Laravel PHP framework. It enables users to create websites and online stores easily without needing to write code. Microweber is popular among small to medium-sized businesses and entrepreneurs for its ease of use, flexibility, and comprehensive features that include e-commerce, blogging, and website customization. It's designed to help users launch their online presence quickly and efficiently.

The vulnerability is specifically found in the logout functionality of Microweber, where the redirect_to parameter is not properly validated. An attacker can craft a URL that includes the malicious redirect_to parameter, and when a user logs out, they are redirected to an attacker-controlled website. This issue arises due to insufficient input validation and sanitization, highlighting the importance of adequately verifying and encoding external input to prevent unintended redirects.

Exploiting this vulnerability could lead to various adverse effects, including phishing attacks, stealing of sensitive information, and damaging the credibility of the affected site. Users might be redirected to malicious sites that appear legitimate but are designed to steal personal, financial, or login information. Such attacks can compromise user privacy and security, and erode trust in the website.

By leveraging the Cyber Threat Exposure Management service provided by S4E, organizations can identify and address vulnerabilities like CVE-2022-0597 in their web applications. Our platform offers comprehensive vulnerability scanning and management solutions, helping businesses to mitigate risks and protect their digital assets against exploitation. Membership grants access to detailed vulnerability reports, real-time monitoring, and expert recommendations, ensuring your online presence is secure and resilient against cyber threats.

 

References

Solution Advice
  1. Update Microweber to version 1.2.11 or later to address the vulnerability.
  2. Implement rigorous input validation and sanitization to prevent malicious redirection.
  3. Regularly scan and test web applications for open redirection and other common vulnerabilities.
  4. Educate users on the risks of phishing and the importance of verifying the authenticity of URLs before clicking.
  5. Monitor and review all third-party plugins and dependencies for known vulnerabilities and ensure they are up to date.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-0597 scanner - Open Redirection vulnerability in Microweber S4E