CVE-2022-33012
PHP vulnerability analysis and mitigation

Overview

Microweber v1.2.15 was discovered to contain an account takeover vulnerability that could be exploited via a host header injection attack. The vulnerability was assigned CVE-2022-33012 and was discovered on June 7, 2022. The vulnerability affects the password reset functionality of Microweber, a popular PHP-based Content Management System with over 2.5k stars on GitHub (Jitendra Blog).

Technical details

The vulnerability is a host header injection flaw in the password reset mechanism. When a password reset is requested, the application accepts arbitrary host headers in the request. The application then uses this host header value to generate the password reset link that is sent to the user's email. This allows an attacker to manipulate the host header and have the password reset link point to a malicious domain instead of the legitimate application domain. The vulnerability has been assigned a CVSS v3.1 Base Score of 8.8 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (NVD).

Impact

The vulnerability allows attackers to perform account takeover by poisoning password reset links. When a victim clicks on the manipulated password reset link, they are directed to the attacker's controlled domain with their valid reset token. This allows the attacker to capture the reset token and use it to change the victim's password, effectively taking over their account (PayloadsAllTheThings).

Mitigation and workarounds

The vendor was notified of the vulnerability on July 1, 2022, but did not respond even after 120 days. As of the public disclosure on October 29, 2022, there was no official patch available. Organizations using Microweber v1.2.15 should validate and sanitize host headers in password reset requests to prevent this vulnerability (Jitendra Blog).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-f25v-x6vr-962gCRITICAL10
  • PHP logoPHP
  • pheditor/pheditor
NoYesJul 24, 2026
GHSA-h4hf-v6w5-897xHIGH8.8
  • PHP logoPHP
  • poweradmin/poweradmin
NoYesJul 24, 2026
GHSA-g3hq-hphg-8fhhHIGH8.8
  • PHP logoPHP
  • pheditor/pheditor
NoYesJul 24, 2026
GHSA-cmwh-g2h8-c222HIGH8.1
  • PHP logoPHP
  • poweradmin/poweradmin
NoYesJul 24, 2026
GHSA-rm67-g9ch-vxffHIGH8.1
  • PHP logoPHP
  • poweradmin/poweradmin
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management