CVE-2024-40101: XSS
A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/microweber/microweberto a version that resolves this vulnerability.Fixed in 2.0.16
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40101?
CVE-2024-40101 is classified as a moderate severity vulnerability due to its potential to allow unauthorized script injection.
How do I fix CVE-2024-40101?
To mitigate CVE-2024-40101, upgrade your Microweber installation to version 2.0.16 or later.
What is CVE-2024-40101?
CVE-2024-40101 is a Reflected Cross-site Scripting (XSS) vulnerability found in the '/search' functionality of Microweber 2.0.15 and earlier.
Who is affected by CVE-2024-40101?
Users running Microweber versions 2.0.15 and earlier are affected by CVE-2024-40101.
Can CVE-2024-40101 be exploited remotely?
Yes, CVE-2024-40101 can be exploited remotely by unauthenticated attackers through the 'keywords' parameter.