CVE-2023-2014: Cross-site Scripting (XSS) - Generic in microweber/microweber
Published Apr 13, 2023
·Updated
Cross-site Scripting (XSS) - Generic in GitHub repository microweber/microweber prior to 1.3.3.
Affected Software
1 affected component
Microweber Microweber<1.3.3
Remediation
Event History
Apr 13, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-2014?
CVE-2023-2014 is a Cross-site Scripting (XSS) vulnerability in the GitHub repository microweber/microweber prior to version 1.3.3.
2
How does CVE-2023-2014 affect Microweber Microweber?
CVE-2023-2014 affects Microweber Microweber versions prior to 1.3.3.
3
What is the severity of CVE-2023-2014?
The severity of CVE-2023-2014 is medium with a CVSS score of 4.8.
4
How can I fix CVE-2023-2014?
To fix CVE-2023-2014, update your Microweber Microweber installation to version 1.3.3 or later.
5
Where can I find more information about CVE-2023-2014?
You can find more information about CVE-2023-2014 in the following references: [GitHub Commit](https://github.com/microweber/microweber/commit/1a9b904722b35b00653c6ae72dca2969149159b3) and [Huntr.dev](https://huntr.dev/bounties/a77bf7ed-6b61-452e-b5ee-e20017e28d1a).