HIGH
Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack
Published Nov 22, 2022
8.8
HIGHCVSS 3.1
EPSS 1.41%
Description
Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.
Affected products
No data.
- 1.2.15
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://blog.jitendrapatro.me/cve-2022-33012-account-takeover-through-password-reset-poisoning ExploitThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7429 Advisory
- https://github.com/advisories/GHSA-rp7f-fhm8-9hpf Advisory
- https://github.com/microweber/microweber ProductThird Party Advisory
- https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Account%20Takeover#account-takeover-through-password-reset-poisoning ExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-33012
- https://www.pethuraj.com/blog/how-i-earned-800-for-host-header-injection-vulnerability Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://blog.jitendrapatro.me/cve-2022-33012-account-takeover-through-password-reset-poisoning | ExploitThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7429 | Advisory | |
| https://github.com/advisories/GHSA-rp7f-fhm8-9hpf | Advisory | |
| https://github.com/microweber/microweber | ProductThird Party Advisory | |
| https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Account%20Takeover#account-takeover-through-password-reset-poisoning | ExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-33012 | ||
| https://www.pethuraj.com/blog/how-i-earned-800-for-host-header-injection-vulnerability | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 22, 2022
Updated Apr 29, 2025
Reserved Jun 13, 2022
Link CVE-2022-33012
CISA Vulnrichment
Updated Apr 29, 2025
Red Hat
No data
GitHub
Link GHSA-RP7F-FHM8-9HPF