CVE-2022-2495: Cross-site Scripting (XSS) - Stored in microweber/microweber
Published Jul 22, 2022
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21.
Affected Software
1 affected component
Microweber Microweber<1.2.21
Remediation
Event History
Jul 22, 2022
CVE Published
via MITRE·03:48 AM
Data Sourced
via MITRE·03:48 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-2495?
CVE-2022-2495 is a vulnerability known as Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to version 1.2.21.
2
What is the severity of CVE-2022-2495?
The severity of CVE-2022-2495 is medium with a CVSS score of 4.8.
3
How can I fix CVE-2022-2495?
To fix CVE-2022-2495, upgrade your Microweber Microweber software to version 1.2.21 or later.
4
Which software versions are affected by CVE-2022-2495?
CVE-2022-2495 affects Microweber Microweber versions up to exclusive version 1.2.21.
5
What is the Common Weakness Enumeration (CWE) for CVE-2022-2495?
The Common Weakness Enumeration (CWE) for CVE-2022-2495 is CWE-79.