5
CVSSv2

CVE-2020-13405

Published: 16/07/2020 Updated: 21/07/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

userfiles/modules/users/controller/controller.php in Microweber prior to 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microweber microweber

Github Repositories

MicroWeber Unauthenticated User Database Disclosure - CVE-2020-13405

CVE-2020-13405 Base Score: 75 HIGH🟥 MicroWeber is an open-source Content Management System (CMS) written in PHP It allows web administrators to easily build a website by dragging and dropping components where they want them to be It is a popular choice among those looking to start a website that is both easy to set up and is very customizable userfiles/modules/users/c