Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://huntr.dev/bounties/0e776f3d-35b1-4a9e-8fe8-91e46c0d6316 | third party advisory exploit |
https://github.com/microweber/microweber/commit/e680e134a4215c979bfd2eaf58336be34c8fc6e6 | third party advisory patch |