CVE-2025-70792: XSS
Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "relid" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20.
Other sources
There is a Cross-site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "relid" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20.
— GitHub
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-70792?
CVE-2025-70792 is considered a critical vulnerability due to its potential for JavaScript code execution in the victim's browser.
How do I fix CVE-2025-70792?
To fix CVE-2025-70792, upgrade to Microweber version 2.0.20 or later.
What type of vulnerability is CVE-2025-70792?
CVE-2025-70792 is a Cross Site Scripting (XSS) vulnerability.
Which software versions are affected by CVE-2025-70792?
CVE-2025-70792 affects Microweber version 2.0.19 and earlier.
How can an attacker exploit CVE-2025-70792?
An attacker can exploit CVE-2025-70792 by manipulating the 'rel_id' parameter in a crafted URL and luring an admin user to visit it.