Generation of Error Message Containing Sensitive Information in microweber/microweber


Reported on

Feb 13th 2022


Sensitive information as part of the error is getting disclosed while viewing comments from "load_module:comments#search="

Proof of Concept

  1. Login to
  2. Visit
  3. Now enter anything in search= parameter you can see 500 internal error with sensitive information


This vulnerability is capable of leaking sensitive data of the system where the website is hosted

We are processing your report and will contact the microweber team within 24 hours. a year ago
a year ago


POC Video :

We have contacted a member of the microweber team and are waiting to hear back a year ago
a year ago


Hello any update?

a year ago


We have sent a follow up to the microweber team. We will try again in 7 days. a year ago
Peter Ivanov validated this vulnerability a year ago
0x2374 has been awarded the disclosure bounty
The fix bounty is now up for grabs
Peter Ivanov marked this as fixed in 1.2.11 with commit 2417bd a year ago
Peter Ivanov has been awarded the fix bounty
This vulnerability will not receive a CVE
search_content.php#L38-L53 has been validated
to join this conversation