CVE-2020-13405
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.
- Affected products
- Microweber
- Microweber
- < 1.1.20
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 13.6% (96th percentile)
- Weakness
- CWE-306
- NVD status
- Modified
- Published
- 2020-07-16
CVE-2020-13405 at NVD
2 known exploits for CVE-2020-13405
Proof-of-concept code and exploit modules indexed by Sploitus