CVE-2022-3242: HTML code Injection in template search keyword in microweber/microweber
Published Sep 20, 2022
·Updated
Code Injection in GitHub repository microweber/microweber prior to 1.3.2.
Affected Software
1 affected component
Microweber Microweber<1.3.2
Remediation
Event History
Sep 20, 2022
CVE Published
via MITRE·10:15 AM
Data Sourced
via MITRE·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-3242?
CVE-2022-3242 is a vulnerability that allows an attacker to inject malicious code into the GitHub repository microweber/microweber prior to version 1.3.2.
2
How does CVE-2022-3242 affect software?
CVE-2022-3242 affects Microweber Microweber versions up to and excluding 1.3.2.
3
What is the severity of CVE-2022-3242?
CVE-2022-3242 has a severity rating of 6.1 (medium).
4
How can I fix the Code Injection vulnerability in Microweber Microweber?
To fix the Code Injection vulnerability in Microweber Microweber, update to version 1.3.2 or later.
5
Where can I find more information about CVE-2022-3242?
More information about CVE-2022-3242 can be found in the references section: [GitHub commit](https://github.com/microweber/microweber/commit/68f0721571653db865a5fa01c7986642c82e919c) and [Huntr.bounties](https://huntr.dev/bounties/3e6b218a-a5a6-40d9-9f7e-5ab0c6214faf).