First published: Tue Mar 15 2022(Updated: )
Unrestricted XML Files Leads to Stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Microweber Microweber | <1.2.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0963 is a vulnerability that allows for stored cross-site scripting (XSS) attacks in the GitHub repository microweber/microweber prior to version 1.2.12.
The vulnerability is caused by unrestricted XML files, which can allow an attacker to inject malicious scripts that are stored and executed by the application.
The severity of the CVE-2022-0963 vulnerability is medium, with a CVSS score of 5.4.
Microweber version prior to 1.2.12 is affected by CVE-2022-0963.
To fix the CVE-2022-0963 vulnerability, update Microweber to version 1.2.12 or later.