
Cloud Vulnerability DB
A community-led vulnerabilities database
Microweber v1.2.15 was discovered to contain an account takeover vulnerability that could be exploited via a host header injection attack. The vulnerability was assigned CVE-2022-33012 and was discovered on June 7, 2022. The vulnerability affects the password reset functionality of Microweber, a popular PHP-based Content Management System with over 2.5k stars on GitHub (Jitendra Blog).
The vulnerability is a host header injection flaw in the password reset mechanism. When a password reset is requested, the application accepts arbitrary host headers in the request. The application then uses this host header value to generate the password reset link that is sent to the user's email. This allows an attacker to manipulate the host header and have the password reset link point to a malicious domain instead of the legitimate application domain. The vulnerability has been assigned a CVSS v3.1 Base Score of 8.8 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (NVD).
The vulnerability allows attackers to perform account takeover by poisoning password reset links. When a victim clicks on the manipulated password reset link, they are directed to the attacker's controlled domain with their valid reset token. This allows the attacker to capture the reset token and use it to change the victim's password, effectively taking over their account (PayloadsAllTheThings).
The vendor was notified of the vulnerability on July 1, 2022, but did not respond even after 120 days. As of the public disclosure on October 29, 2022, there was no official patch available. Organizations using Microweber v1.2.15 should validate and sanitize host headers in password reset requests to prevent this vulnerability (Jitendra Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."