CVE-2024-33297: XSS
Published Jan 10, 2025
·Updated
Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add new campaign function
Affected Software
2 affected components
composer/microweber/microweber<=2.0.9
Microweber Microweber<=2.0.9
Event History
Jan 10, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
Affected Software
Advisory Published
via GitHub·09:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-33297?
CVE-2024-33297 is considered a high-severity cross-site scripting vulnerability.
2
How do I fix CVE-2024-33297?
To fix CVE-2024-33297, upgrade Microweber to a version beyond 2.0.9 that addresses this vulnerability.
3
Who is affected by CVE-2024-33297?
CVE-2024-33297 affects users of Microweber version 2.0.9 and earlier.
4
What can an attacker do with CVE-2024-33297?
An attacker can execute arbitrary code by exploiting the cross-site scripting vulnerability in the campaign name field.
5
When was CVE-2024-33297 disclosed?
CVE-2024-33297 was disclosed in 2024.