Products
microweber
- 2.0.15 and earlier
Source
cve@mitre.org
Tags
CVE-2024-40101 details
Published : Aug. 6, 2024, 2:16 p.m.
Last Modified : Aug. 6, 2024, 4:30 p.m.
Last Modified : Aug. 6, 2024, 4:30 p.m.
Description
A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|
References
URL | Source |
---|---|
http://microweber.com | cve@mitre.org |
https://github.com/microweber/microweber/commit/0dede6886c6df3d1f31c4f4e3ba1ab4a336fbf79 | cve@mitre.org |
https://seclists.org/fulldisclosure/2024/Aug/1 | cve@mitre.org |
This website uses the NVD API, but is not approved or certified by it.