Filtered by vendor Microweber
Subscriptions
Filtered by product Microweber
Subscriptions
Total
101 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2023-5244 | 1 Microweber | 1 Microweber | 2024-11-21 | 6.1 Medium |
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 2.0. | ||||
CVE-2023-49052 | 1 Microweber | 1 Microweber | 2024-11-21 | 8.8 High |
File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function in the created forms component. | ||||
CVE-2023-48122 | 1 Microweber | 1 Microweber | 2024-11-21 | 7.5 High |
An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method. | ||||
CVE-2023-47379 | 1 Microweber | 1 Microweber | 2024-11-21 | 5.4 Medium |
Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality. | ||||
CVE-2023-1081 | 1 Microweber | 1 Microweber | 2024-11-21 | 4.8 Medium |
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3. | ||||
CVE-2022-3245 | 1 Microweber | 1 Microweber | 2024-11-21 | 6.1 Medium |
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input. | ||||
CVE-2022-3242 | 1 Microweber | 1 Microweber | 2024-11-21 | 6.1 Medium |
Code Injection in GitHub repository microweber/microweber prior to 1.3.2. | ||||
CVE-2022-33012 | 1 Microweber | 1 Microweber | 2024-11-21 | 8.8 High |
Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack. | ||||
CVE-2022-2777 | 1 Microweber | 1 Microweber | 2024-11-21 | 5.4 Medium |
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.1. | ||||
CVE-2022-2495 | 1 Microweber | 1 Microweber | 2024-11-21 | 4.8 Medium |
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21. | ||||
CVE-2022-2470 | 1 Microweber | 1 Microweber | 2024-11-21 | 6.1 Medium |
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21. | ||||
CVE-2022-2368 | 1 Microweber | 1 Microweber | 2024-11-21 | 6.5 Medium |
Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20. | ||||
CVE-2022-2353 | 1 Microweber | 1 Microweber | 2024-11-21 | 6.1 Medium |
Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user. | ||||
CVE-2022-2300 | 1 Microweber | 1 Microweber | 2024-11-21 | 5.4 Medium |
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19. | ||||
CVE-2022-2280 | 1 Microweber | 1 Microweber | 2024-11-21 | 5.4 Medium |
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19. | ||||
CVE-2022-2252 | 1 Microweber | 1 Microweber | 2024-11-21 | 6.1 Medium |
Open Redirect in GitHub repository microweber/microweber prior to 1.2.19. | ||||
CVE-2022-2174 | 1 Microweber | 1 Microweber | 2024-11-21 | 6.1 Medium |
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18. | ||||
CVE-2022-2130 | 1 Microweber | 1 Microweber | 2024-11-21 | 6.1 Medium |
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17. | ||||
CVE-2022-1631 | 1 Microweber | 1 Microweber | 2024-11-21 | 8.8 High |
Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account in the application using the Victim’s Email. This allows an attacker to gain pre-authentication to the victim’s account. Further, due to the lack of proper validation of email coming from Social Login and failing to check if an account already exists, the victim will not identify if an account is already existing. Hence, the attacker’s persistence will remain. An attacker would be able to see all the activities performed by the victim user impacting the confidentiality and attempt to modify/corrupt the data impacting the integrity and availability factor. This attack becomes more interesting when an attacker can register an account from an employee’s email address. Assuming the organization uses G-Suite, it is much more impactful to hijack into an employee’s account. | ||||
CVE-2022-1584 | 1 Microweber | 1 Microweber | 2024-11-21 | 6.1 Medium |
Reflected XSS in GitHub repository microweber/microweber prior to 1.2.16. Executing JavaScript as the victim |