CVE-2024-33299: XSS
Published Jan 10, 2025
·Updated
Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the endpoint /admin/module/view?type=users
Affected Software
2 affected components
composer/microweber/microweber<=2.0.9
Microweber Microweber<=2.0.9
Event History
Jan 10, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
Affected Software
Advisory Published
via GitHub·09:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-33299?
CVE-2024-33299 is categorized as a high-severity Cross-Site Scripting vulnerability.
2
How do I fix CVE-2024-33299?
To fix CVE-2024-33299, it is recommended to update Microweber to version 2.0.10 or later.
3
What software versions are affected by CVE-2024-33299?
CVE-2024-33299 affects Microweber version 2.0.9 and earlier.
4
How can CVE-2024-33299 be exploited by attackers?
Attackers can exploit CVE-2024-33299 by injecting malicious scripts through the First Name and Last Name parameters in the specified endpoint.
5
Is CVE-2024-33299 related to unauthorized data access?
Yes, CVE-2024-33299 could potentially lead to unauthorized data access due to the execution of arbitrary code.