First published: Fri Nov 25 2022(Updated: )
Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter.
Credit: help@fluidattacks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microweber Microweber | =1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0698 is a vulnerability in Microweber version 1.3.1 that allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter.
CVE-2022-0698 has a severity level of medium with a CVSS score of 6.1.
An unauthenticated user can perform an account takeover by exploiting an XSS vulnerability in the 'select-file' parameter of Microweber version 1.3.1.
Microweber version 1.3.1 is the affected software version for CVE-2022-0698.
The fix for CVE-2022-0698 is not yet available. It is recommended to update to a newer version when it becomes available or apply any patches or workarounds provided by the vendor.