CVE-2018-19917: XSS
Published Mar 17, 2019
·Updated
Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities.
Affected Software
2 affected components
composer/microweber/microweber<=1.0.8
Microweber Microweber=1.0.8
Event History
Mar 17, 2019
CVE Published
via MITRE·07:21 PM
Data Sourced
via MITRE·07:21 PM
Description
May 14, 2022
Advisory Published
01:07 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-19917?
CVE-2018-19917 has a moderate severity rating due to its potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2018-19917?
To fix CVE-2018-19917, upgrade to a patched version of Microweber that addresses the reflected XSS vulnerabilities.
3
Who is affected by CVE-2018-19917?
CVE-2018-19917 affects users of Microweber version 1.0.8 who may be exposed to reflected XSS attacks.
4
What is reflected cross-site scripting in the context of CVE-2018-19917?
Reflected cross-site scripting in CVE-2018-19917 allows attackers to execute scripts in the context of the user's browser by abusing input fields.
5
Can CVE-2018-19917 be exploited without user interaction?
Yes, CVE-2018-19917 can be exploited by tricking users into clicking malicious links that exploit the XSS vulnerabilities.