GHSA-232p-59mg-f98p
Dashboard / Vulnerabilities / GHSA-232p-59mg-f98p
Summary: Microweber Cross-site Scripting can result in redirection to a malicious site
Details: Microweber versions 1.3.1 and prior are vulnerable to HTML injection that an attacker can use to redirect someone to a malicious site. A patch is available at commit 68f0721571653db865a5fa01c7986642c82e919c and expected to be part of version 1.3.2.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-3242, https://github.com/microweber/microweber/commit/68f0721571653db865a5fa01c7986642c82e919c, https://github.com/microweber/microweber, https://huntr.dev/bounties/3e6b218a-a5a6-40d9-9f7e-5ab0c6214faf
Affected packages
Package
Name: microweber/microweber
Purl: pkg:composer/microweber/microweber
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -1.3.2
Affected versions
0.9.346
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
