CVE-2022-0698: XSS
Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-0698?
CVE-2022-0698 is a vulnerability in Microweber version 1.3.1 that allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter.
How severe is CVE-2022-0698?
CVE-2022-0698 has a severity level of medium with a CVSS score of 6.1.
How can an unauthenticated user perform an account takeover using CVE-2022-0698?
An unauthenticated user can perform an account takeover by exploiting an XSS vulnerability in the 'select-file' parameter of Microweber version 1.3.1.
What is the affected software version for CVE-2022-0698?
Microweber version 1.3.1 is the affected software version for CVE-2022-0698.
Is there a fix available for CVE-2022-0698?
The fix for CVE-2022-0698 is not yet available. It is recommended to update to a newer version when it becomes available or apply any patches or workarounds provided by the vendor.