Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-cf6r-q678-f2p7: Cross-site Scripting in microweber

In Microweber prior to v1.3.1, the title parameter in the body of POST request when creating/editing a category is vulnerable to stored cross-site scripting.

ghsa
#xss#web#git

Cross-site Scripting in microweber

Moderate severity GitHub Reviewed Published Aug 12, 2022 • Updated Aug 12, 2022

Related news

CVE-2022-2777: update · microweber/microweber@60eef74

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.1.