CVE-2023-3142: Cross-site Scripting (XSS) - Stored in microweber/microweber
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0.
Other sources
Microweber 1.3.4 and prior is vulnerable to stored cross-site scripting via an alert on the Editing page. This issue is fixed in commit 42efa981a2239d042d910069952d6276497bdcf1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
microweber/microweberto a version that resolves this vulnerability.Patch 42efa981a2239d042d910069952d6276497bdcf1
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3142?
The severity of CVE-2023-3142 is medium with a CVSS score of 5.4.
What is the vulnerability type of CVE-2023-3142?
CVE-2023-3142 is a Cross-site Scripting (XSS) vulnerability.
Which software versions are affected by CVE-2023-3142?
Versions of Microweber Microweber prior to 2.0 are affected by CVE-2023-3142.
How can I fix CVE-2023-3142?
To fix CVE-2023-3142, update Microweber Microweber to version 2.0 or above.
Where can I find more information about CVE-2023-3142?
You can find more information about CVE-2023-3142 at the following references: [GitHub Commit](https://github.com/microweber/microweber/commit/42efa981a2239d042d910069952d6276497bdcf1), [Huntr Bounty](https://huntr.dev/bounties/d00686b0-f89a-4e14-98d7-b8dd3f92a6e5).