← Back

Microweber

microweber

Vendor: Microweber • 114 CVEs

CVEs (114)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microweber
1Microweber
Nov 21, 2024
Sep 20, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validatio...Show more
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input.Show less
1Microweber
1Microweber
Nov 21, 2024
Sep 20, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Code Injection in GitHub repository microweber/microweber prior to 1.3.2.
1Microweber
1Microweber
Nov 21, 2024
Aug 11, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.1.
1Microweber
1Microweber
Nov 21, 2024
Jul 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21.
1Microweber
1Microweber
Nov 21, 2024
Jul 22, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21.
1Microweber
1Microweber
Nov 21, 2024
Jul 15, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini.
1Microweber
1Microweber
Feb 25, 2026
Jul 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.
1Microweber
1Microweber
Nov 21, 2024
Jul 9, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user.
1Microweber
1Microweber
Nov 21, 2024
Jul 4, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.
1Microweber
1Microweber
Nov 21, 2024
Jul 1, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.
1Microweber
1Microweber
Nov 21, 2024
Jun 29, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.
1Microweber
1Microweber
Nov 21, 2024
Jun 22, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.
1Microweber
1Microweber
Nov 21, 2024
Jun 20, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17.
1Microweber
1Microweber
Nov 21, 2024
May 9, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account...Show more
Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account in the application using the Victim’s Email. This allows an attacker to gain pre-authentication to the victim’s account. Further, due to the lack of proper validation of email coming from Social Login and failing to check if an account already exists, the victim will not identify if an account is already existing. Hence, the attacker’s persistence will remain. An attacker would be able to see all the activities performed by the victim user impacting the confidentiality and attempt to modify/corrupt the data impacting the integrity and availability factor. This attack becomes more interesting when an attacker can register an account from an employee’s email address. Assuming the organization uses G-Suite, it is much more impactful to hijack into an employee’s account.Show less
1Microweber
1Microweber
Nov 21, 2024
May 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected XSS in GitHub repository microweber/microweber prior to 1.2.16. Executing JavaScript as the victim
1Microweber
1Microweber
Nov 21, 2024
May 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DOM XSS in microweber ver 1.2.15 in GitHub repository microweber/microweber prior to 1.2.16. inject arbitrary js code, deface website, steal cookie...
1Microweber
1Microweber
Nov 21, 2024
Apr 27, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS in /demo/module/?module=HERE in GitHub repository microweber/microweber prior to 1.2.15. Typical impact of XSS attacks.
1Microweber
1Microweber
Nov 21, 2024
Apr 22, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected XSS on demo.microweber.org/demo/module/ in GitHub repository microweber/microweber prior to 1.2.15. Execute Arbitrary JavaScript as the attacked user. It's the only payload I found working, you might need to pr...Show more
Reflected XSS on demo.microweber.org/demo/module/ in GitHub repository microweber/microweber prior to 1.2.15. Execute Arbitrary JavaScript as the attacked user. It's the only payload I found working, you might need to press "tab" but there is probably a paylaod that runs without user interaction.Show less
1Microweber
1Microweber
Nov 21, 2024
Mar 22, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12.
1Microweber
1Microweber
Nov 21, 2024
Mar 15, 2022
N/A· v4
5.5 MEDIUM· v3
4.0 MEDIUM· v2
The microweber application allows large characters to insert in the input field "fist & last name" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in microweber/microweber in GitH...Show more
The microweber application allows large characters to insert in the input field "fist & last name" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in microweber/microweber in GitHub repository microweber/microweber prior to 1.2.12.Show less