XSS Vulnerability in Microweber by Microweber
CVE-2024-41380
Currently unrated
What is CVE-2024-41380?
Microweber 2.0.16 is vulnerable to a Cross-Site Scripting (XSS) attack, which can allow attackers to inject malicious scripts into web pages viewed by other users. This vulnerability is exploited via the userfiles/modules/tags/add_tagging_tagged.php file, potentially compromising user sessions and sensitive data. It is crucial for users of this version to apply the necessary patches to mitigate risks associated with this security flaw.