Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hrf4-hcpc-3345

Опубликовано: 16 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.1

Описание

Denial of service in microweber

Microweber is drag and drop website builder and CMS with E-commerce. The microweber prior 1.2.12 application allows large characters to insert in the input field "post title" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. The post title input can be limited to 500 characters or max 1000 characters as a workaround.

Пакеты

Наименование

microweber/microweber

composer
Затронутые версииВерсия исправления

<= 1.2.11

Отсутствует

EPSS

Процентиль: 83%
0.01843
Низкий

7.1 High

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 5.5
nvd
почти 4 года назад

The microweber application allows large characters to insert in the input field "post title" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in GitHub repository microweber/microweber prior to 1.2.12.

EPSS

Процентиль: 83%
0.01843
Низкий

7.1 High

CVSS3

Дефекты

CWE-190