Vulnerabilities
Vulnerable Software
Microweber:  >> Microweber  >> 1.0.6  Security Vulnerabilities
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.
CVSS Score
6.3
EPSS Score
0.002
Published
2022-07-04
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.
CVSS Score
6.5
EPSS Score
0.003
Published
2022-07-01
Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.
CVSS Score
4.3
EPSS Score
0.002
Published
2022-06-29
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.
CVSS Score
6.5
EPSS Score
0.17
Published
2022-06-22
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17.
CVSS Score
6.5
EPSS Score
0.109
Published
2022-06-20
Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account in the application using the Victim’s Email. This allows an attacker to gain pre-authentication to the victim’s account. Further, due to the lack of proper validation of email coming from Social Login and failing to check if an account already exists, the victim will not identify if an account is already existing. Hence, the attacker’s persistence will remain. An attacker would be able to see all the activities performed by the victim user impacting the confidentiality and attempt to modify/corrupt the data impacting the integrity and availability factor. This attack becomes more interesting when an attacker can register an account from an employee’s email address. Assuming the organization uses G-Suite, it is much more impactful to hijack into an employee’s account.
CVSS Score
6.8
EPSS Score
0.043
Published
2022-05-09
Reflected XSS in GitHub repository microweber/microweber prior to 1.2.16. Executing JavaScript as the victim
CVSS Score
6.3
EPSS Score
0.003
Published
2022-05-04
DOM XSS in microweber ver 1.2.15 in GitHub repository microweber/microweber prior to 1.2.16. inject arbitrary js code, deface website, steal cookie...
CVSS Score
8.8
EPSS Score
0.009
Published
2022-05-04
XSS in /demo/module/?module=HERE in GitHub repository microweber/microweber prior to 1.2.15. Typical impact of XSS attacks.
CVSS Score
6.3
EPSS Score
0.003
Published
2022-04-27
Reflected XSS on demo.microweber.org/demo/module/ in GitHub repository microweber/microweber prior to 1.2.15. Execute Arbitrary JavaScript as the attacked user. It's the only payload I found working, you might need to press "tab" but there is probably a paylaod that runs without user interaction.
CVSS Score
6.3
EPSS Score
0.383
Published
2022-04-22


Contact Us

Shodan ® - All rights reserved