
Cloud Vulnerability DB
A community-led vulnerabilities database
A sensitive information exposure vulnerability was identified in Packagist microweber/microweber versions prior to 1.2.11. The vulnerability was assigned CVE-2022-0281 and was recorded on January 19, 2022 (CVE MITRE).
The vulnerability involves exposure of sensitive information to unauthorized actors in the Packagist microweber/microweber package. The issue was specifically related to the search_authors functionality in the API user helpers, which was modified to restrict access to administrators only (Github Commit).
The vulnerability could potentially lead to unauthorized access to sensitive information by malicious actors who are not administrators of the system (NVD).
The vulnerability was addressed in version 1.2.11 of microweber/microweber. The fix involved modifying the API exposure of the search_authors function to restrict it to admin users only (Github Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."