First published: Wed Nov 08 2023(Updated: )
Microweber CMS prior to version 2.0.3 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/microweber/microweber | <2.0.3 | 2.0.3 |
Microweber Microweber | =2.0.1 | |
=2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-47379 is a vulnerability in Microweber CMS that allows for stored Cross Site Scripting (XSS) attacks via the profile picture file upload functionality.
CVE-2023-47379 affects Microweber CMS versions prior to 2.0.3.
The impact of CVE-2023-47379 is that it allows an attacker to execute malicious scripts in the context of the victim's browser, potentially leading to account hijacking, data theft, or other malicious activities.
To fix CVE-2023-47379, upgrade Microweber CMS to version 2.0.3 or higher.
You can find more information about CVE-2023-47379 in the references provided: [link1](https://www.getastra.com/blog/security-audit/stored-xss-vulnerability/), [link2](https://github.com/microweber/microweber/commit/c6e7ea9d0abd7564a3bb23c14ad172e4ccf27a7e#diff-fac4e7e9eca69c10d074bf8c5eac7f64b018c6b4d91dcad54b340a8560049e00), [link3](https://github.com/microweber/microweber/blob/master/CHANGELOG.md)