CVE-2025-70791: XSS
Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20.
Other sources
Cross-site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20.
— GitHub
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-70791?
CVE-2025-70791 is classified as a Cross Site Scripting vulnerability with a high severity due to its potential for JavaScript code execution in a victim's browser.
How do I fix CVE-2025-70791?
To fix CVE-2025-70791, upgrade Microweber to version 2.0.20 or later.
What impact does CVE-2025-70791 have on my system?
CVE-2025-70791 allows an attacker to execute arbitrary JavaScript code in the browser of an admin user, potentially compromising sensitive information.
Who is affected by CVE-2025-70791?
CVE-2025-70791 affects users of Microweber version 2.0.19 and earlier.
How can an attacker exploit CVE-2025-70791?
An attacker can exploit CVE-2025-70791 by crafting a malicious URL that manipulates the 'orderDirection' parameter and tricking an admin user into visiting it.