CVE-2022-1036
Dashboard / Vulnerabilities / CVE-2022-1036
Summary: Able to create an account with long password leads to memory corruption / Integer Overflow in microweber/microweber
Details: Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12.
References: https://huntr.dev/bounties/db615581-d5a9-4ca5-a3e9-7a39eceaa424, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1036.json, https://nvd.nist.gov/vuln/detail/CVE-2022-1036, https://github.com/microweber/microweber/commit/82be4f0b4729be870ccefdae99a04833f134aa6a
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
v1.2.11
v1.2.10
v1.2.9
v1.2.8
v1.2.7
v1.2.6
v1.2.5
v1.2.4
v1.2.3
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
