Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-1439

Reflected XSS on demo.microweber.org/demo/module/ in GitHub repository microweber/microweber prior to 1.2.15. Execute Arbitrary JavaScript as the attacked user. It's the only payload I found working, you might need to press "tab" but there is probably a paylaod that runs without user interaction.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.383
EPSS Ranking 97.1%
CVSS Severity
CVSS v3 Score 6.3
CVSS v2 Score 4.3
Products affected by CVE-2022-1439


Contact Us

Shodan ® - All rights reserved