SB2019032136 - Cross-site scripting in Microweber
Published: March 21, 2019 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cross-site scripting (CVE-ID: CVE-2018-19917)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities.
Remediation
Install update from vendor's website.
References
- http://packetstormsecurity.com/files/151005/Microweber-1.0.8-Cross-Site-Scripting.html
- http://seclists.org/fulldisclosure/2019/Jan/12
- http://seclists.org/fulldisclosure/2019/Jan/25
- https://github.com/microweber/microweber/commits/master
- https://www.netsparker.com/web-applications-advisories/ns-18-038-reflected-cross-site-scripting-in-microweber/