Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Attackers can input script payloads in the first name field that will execute when the profile is viewed by other users, potentially stealing session cookies and executing arbitrary JavaScript.
Metrics
Affected Vendors & Products
References
History
Fri, 12 Dec 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microweber
Microweber microweber |
|
| Vendors & Products |
Microweber
Microweber microweber |
Thu, 11 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Attackers can input script payloads in the first name field that will execute when the profile is viewed by other users, potentially stealing session cookies and executing arbitrary JavaScript. | |
| Title | Microweber 2.0.15 Stored Cross-Site Scripting via User Profile Fields | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-11T21:34:21.705Z
Updated: 2025-12-11T21:34:21.705Z
Reserved: 2025-12-10T23:46:14.009Z
Link: CVE-2024-58289
No data.
Status : Awaiting Analysis
Published: 2025-12-11T22:15:49.557
Modified: 2025-12-12T15:17:31.973
Link: CVE-2024-58289
No data.