CVE-2023-47379: XSS
Microweber CMS prior to version 2.0.3 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality.
Other sources
Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-47379?
CVE-2023-47379 is a vulnerability in Microweber CMS that allows for stored Cross Site Scripting (XSS) attacks via the profile picture file upload functionality.
How does CVE-2023-47379 affect Microweber CMS?
CVE-2023-47379 affects Microweber CMS versions prior to 2.0.3.
What is the impact of CVE-2023-47379?
The impact of CVE-2023-47379 is that it allows an attacker to execute malicious scripts in the context of the victim's browser, potentially leading to account hijacking, data theft, or other malicious activities.
How can I fix CVE-2023-47379 in Microweber CMS?
To fix CVE-2023-47379, upgrade Microweber CMS to version 2.0.3 or higher.
Where can I find more information about CVE-2023-47379?
You can find more information about CVE-2023-47379 in the references provided: [link1](https://www.getastra.com/blog/security-audit/stored-xss-vulnerability/), [link2](https://github.com/microweber/microweber/commit/c6e7ea9d0abd7564a3bb23c14ad172e4ccf27a7e#diff-fac4e7e9eca69c10d074bf8c5eac7f64b018c6b4d91dcad54b340a8560049e00), [link3](https://github.com/microweber/microweber/blob/master/CHANGELOG.md)