漏洞描述
Microweber before 1.2.12 is susceptible to integer overflow. The application allows large characters to insert in the input field 'first & last name,' which can allow an attacker to cause a denial of service via a crafted HTTP request.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
huntr.devhttps://huntr.dev/bounties/97e36678-11cf-42c6-889c-892d415d9f9e/↗github.comhttps://github.com/advisories/GHSA-5fxv-xx5p-g2fv↗huntr.devhttps://huntr.dev/bounties/97e36678-11cf-42c6-889c-892d415d9f9e↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2022-0968↗github.comhttps://github.com/microweber/microweber/commit/80e39084729a57dfe749626c3b9d35247a14c49e↗