CVE-2024-41381: XSS
Published Aug 5, 2024
·Updated
microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php.
Affected Software
2 affected components
composer/microweber/microweber<=2.0.16
Microweber Microweber=2.0.16
Event History
Aug 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
Affected Software
Advisory Published
via GitHub·06:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-41381?
CVE-2024-41381 is rated as a medium severity vulnerability due to its Cross Site Scripting (XSS) nature.
2
How do I fix CVE-2024-41381?
To fix CVE-2024-41381, upgrade to a version of Microweber later than 2.0.16 that has addressed the XSS vulnerability.
3
What components are affected by CVE-2024-41381?
CVE-2024-41381 specifically affects Microweber version 2.0.16, targeting the admin settings module.
4
Is CVE-2024-41381 exploitable remotely?
Yes, CVE-2024-41381 is remotely exploitable, allowing attackers to execute scripts in the context of the user's browser.
5
What impact does CVE-2024-41381 have on users?
CVE-2024-41381 can lead to session hijacking, data theft, or defacement of web applications through the exploitation of XSS.