CVE-2022-1631

HIGH

microweber < 1.2.15 - Unauthenticated Account Takeover via Email Registration

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-1631. PoCs published by Manojkumar J.

AI-analyzed exploit summary This exploit describes an account takeover vulnerability in Microweber CMS 1.2.15 due to OAuth misconfiguration. An attacker can create an account with a victim's email and hijack it when the victim logs in via OAuth providers.

Description

Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account in the application using the Victim’s Email. This allows an attacker to gain pre-authentication to the victim’s account. Further, due to the lack of proper validation of email coming from Social Login and failing to check if an account already exists, the victim will not identify if an account is already existing. Hence, the attacker’s persistence will remain. An attacker would be able to see all the activities performed by the victim user impacting the confidentiality and attempt to modify/corrupt the data impacting the integrity and availability factor. This attack becomes more interesting when an attacker can register an account from an employee’s email address. Assuming the organization uses G-Suite, it is much more impactful to hijack into an employee’s account.

Exploits (1)

exploitdb WRITEUP
by Manojkumar J · textwebappsphp
https://www.exploit-db.com/exploits/50947

This exploit describes an account takeover vulnerability in Microweber CMS 1.2.15 due to OAuth misconfiguration. An attacker can create an account with a victim's email and hijack it when the victim logs in via OAuth providers.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Microweber CMS <=1.2.15
No auth needed
Prerequisites: Victim's email address · Access to registration endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Patch, Third Party Advisory x_refsource_confirm
https://huntr.dev/bounties/5494e258-5c7b-44b4-b443-85cff7ae0ba4
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/167376/Microweber-CMS-1.2.15-Account-Takeover.html

Scores

CVSS v3 8.8
EPSS 0.1515
EPSS Percentile 94.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-284 CWE-863
Status published
Products (2)
microweber/microweber < 1.2.15
microweber/microweber 0 - 1.2.15Packagist
Published May 09, 2022
Tracked Since Feb 18, 2026