Reflected Cross-Site Scripting Vulnerability in Microweber Web Application
CVE-2024-40101
6.1MEDIUM
What is CVE-2024-40101?
A reflected Cross-Site Scripting vulnerability exists in the '/search' endpoint of the Microweber web application, specifically in versions 2.0.15 and earlier. This issue allows unauthenticated remote attackers to inject malicious web scripts or HTML through the 'keywords' parameter. Successful exploitation could enable attackers to execute arbitrary scripts in users' browsers, potentially leading to session hijacking, phishing, or further attacks on other user systems.