Generation of Error Message Containing Sensitive Information in microweber/microweber


Reported on

Feb 13th 2022


Sensitive information as part of the error is getting disclosed while viewing comments from "load_module:comments#search="

Proof of Concept

  1. Login to
  2. Visit
  3. Now enter anything in search= parameter you can see 500 internal error with sensitive information


This vulnerability is capable of leaking sensitive data of the system where the website is hosted

We are processing your report and will contact the microweber team within 24 hours. 3 months ago
3 months ago


POC Video :

We have contacted a member of the microweber team and are waiting to hear back 3 months ago
3 months ago


Hello any update?

3 months ago


We have sent a follow up to the microweber team. We will try again in 7 days. 3 months ago
Peter Ivanov validated this vulnerability 3 months ago
0x2374 has been awarded the disclosure bounty
The fix bounty is now up for grabs
Peter Ivanov confirmed that a fix has been merged on 2417bd 3 months ago
Peter Ivanov has been awarded the fix bounty
search_content.php#L38-L53 has been validated
to join this conversation