CVE-2024-33298: XSS
Published Jan 10, 2025
·Updated
Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=adminbackup
Affected Software
2 affected components
composer/microweber/microweber<=2.0.9
Microweber Microweber<=2.0.9
Event History
Jan 10, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
Affected Software
Advisory Published
via GitHub·09:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-33298?
CVE-2024-33298 is considered a high severity vulnerability due to its ability to allow remote code execution.
2
How can I fix CVE-2024-33298?
To fix CVE-2024-33298, upgrade Microweber to version 2.0.10 or later to mitigate the XSS vulnerability.
3
What type of vulnerability is CVE-2024-33298?
CVE-2024-33298 is categorized as a Cross Site Scripting (XSS) vulnerability affecting Microweber.
4
Who is affected by CVE-2024-33298?
Users of Microweber version 2.0.9 are affected by CVE-2024-33298.
5
What component of Microweber is vulnerable in CVE-2024-33298?
The vulnerability in CVE-2024-33298 affects the create new backup function in the /admin/module/view?type=admin__backup endpoint.