GHSA-gmh3-x5w7-jg5m
Dashboard / Vulnerabilities / GHSA-gmh3-x5w7-jg5m
Summary: Microweber before v1.2.20 vulnerable to cross-site scripting
Details: Prior to Microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery (CSRF), fetch contents from same-site and redirect a user.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-2353, https://github.com/microweber/microweber/commit/79c6914bab8c9da07ac950fda17648d08c68b130, https://github.com/microweber/microweber, https://huntr.dev/bounties/7782c095-9e8c-48b0-a7f5-3a8f52e8af52
Affected packages
Package
Name: microweber/microweber
Purl: pkg:composer/microweber/microweber
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -1.2.20
Affected versions
0.9.346
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
