Improper Handling of Length Parameter Inconsistency in microweber/microweber


Reported on

Feb 17th 2022


There is no input field length in update username where any user can able to add large number of characters like imagine we can add more 5000+ character on to the update name field .

Steps to Reproduce

  • Visit the particular URL Vulnerable-link
  • Where there is a functionality to update our own profile
  • In the name field , Enter the following payload now update the profile
  • As you can see without any length validation , our payload got updated on to the profile

Impact of this Vulnerability:

An attacker would make use of this vulnerability and this leads to

  • Memory corruption
  • Denial of Service


Remediation: We can fix this by implementing a character limit where any user or admin can enter only 255 characters and not more than 255 character on the input field


We are processing your report and will contact the microweber team within 24 hours. a year ago
a year ago


Peter Ivanov validated this vulnerability a year ago
Nithissh12 has been awarded the disclosure bounty
The fix bounty is now up for grabs
Peter Ivanov marked this as fixed in 1.2.11 with commit 62333f a year ago
Peter Ivanov has been awarded the fix bounty
This vulnerability will not receive a CVE
my_profile_admin.php#L1-L81 has been validated
a year ago


There isn't a CVE assigned for this case ?

a year ago



Jamie Slome
a year ago


I have responded to your e-mail.

to join this conversation