CVE-2022-0666 describes a CRLF Injection vulnerability in Microweber prior to version 1.2.11, specifically demonstrated on demo.microweber.org. This flaw allows for Stack Trace Exposure due to insufficient input filtering. With a CVSS score of 7.5 (High), this vulnerability can be exploited remotely without user interaction, potentially leading to information disclosure. While there is no evidence of active exploitation or Metasploit modules, Nuclei templates exist for detecting this high-severity issue, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.11CPE matchmatch criteria | cpe:2.3:a:microweber:microweber:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.