Vulnerabilities
Vulnerable Software
Microweber:  Security Vulnerabilities
Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.
CVSS Score
5.7
EPSS Score
0.002
Published
2022-02-08
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVSS Score
7.7
EPSS Score
0.002
Published
2022-02-08
Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.
CVSS Score
7.1
EPSS Score
0.091
Published
2022-01-26
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVSS Score
8.1
EPSS Score
0.003
Published
2022-01-26
Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11.
CVSS Score
4.3
EPSS Score
0.007
Published
2022-01-20
Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.
CVSS Score
7.5
EPSS Score
0.342
Published
2022-01-20
Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.
CVSS Score
6.5
EPSS Score
0.003
Published
2022-01-20
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVSS Score
7.2
EPSS Score
0.002
Published
2022-01-20
Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by Inserting code in the request form.
CVSS Score
6.1
EPSS Score
0.008
Published
2021-10-19
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload a maliciously constructed ZIP file with file paths including relative paths (i.e., ../../), move this file into the backup directory, and execute a restore on this file.
CVSS Score
7.2
EPSS Score
0.141
Published
2021-02-15


Contact Us

Shodan ® - All rights reserved