XSS Vulnerability in Microweber by Microweber
CVE-2024-41380

Currently unrated

Key Information:

Vendor
Microweber
Vendor
CVE Published:
5 August 2024

Summary

Microweber 2.0.16 is vulnerable to a Cross-Site Scripting (XSS) attack, which can allow attackers to inject malicious scripts into web pages viewed by other users. This vulnerability is exploited via the userfiles/modules/tags/add_tagging_tagged.php file, potentially compromising user sessions and sensitive data. It is crucial for users of this version to apply the necessary patches to mitigate risks associated with this security flaw.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.