userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://github.com/microweber/microweber/commit/269320e0e0e06a1785e1a1556da769a34280b7e6 | third party advisory patch |
https://rhinosecuritylabs.com/research/microweber-database-disclosure/ | third party advisory exploit |