Stored Cross-Site Scripting Vulnerability in Microweber by Microweber
CVE-2024-58289
Key Information:
- Vendor
Microweber
- Status
- Vendor
- CVE Published:
- 11 December 2025
Badges
What is CVE-2024-58289?
Microweber 2.0.15 features a stored cross-site scripting (XSS) vulnerability that exposes user profiles to potential attacks. Authenticated users can exploit this flaw by injecting malicious scripts through the first name field in user profiles. Once this scripted payload is saved, it executes when other users view the profile, potentially allowing the attacker to steal sensitive session cookies and run arbitrary JavaScript. This vulnerability underscores the importance of secure input validation and user profile management in web applications.
Affected Version(s)
Microweber 2.0.15
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
