Microweber before 1.1.20 is susceptible to information disclosure via userfiles/modules/users/controller/controller.php. An attacker can disclose the users database via a /modules/ POST request and thus potentially access sensitive information, modify data, and/or execute unauthorized operations.
id: CVE-2020-13405
info:
name: Microweber <1.1.20 - Information Disclosure
author: ritikchaddha
...