CVE-2022-0278
- EPSS 0.21%
- Veröffentlicht 20.01.2022 10:15:09
- Zuletzt bearbeitet 21.11.2024 06:38:17
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVE-2021-33988
- EPSS 0.83%
- Veröffentlicht 19.10.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:09:51
Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by Inserting code in the request form.
CVE-2020-28337
- EPSS 13.81%
- Veröffentlicht 15.02.2021 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:22:36
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of a...
CVE-2020-23136
- EPSS 0.05%
- Veröffentlicht 09.11.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:13:35
Microweber v1.1.18 is affected by no session expiry after log-out.
CVE-2020-23138
- EPSS 0.43%
- Veröffentlicht 09.11.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:13:35
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php ex...
CVE-2020-23139
- EPSS 0.05%
- Veröffentlicht 09.11.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:13:35
Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise.
CVE-2020-23140
- EPSS 0.27%
- Veröffentlicht 09.11.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:13:35
Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session does not expire and remains active.
CVE-2020-13405
- EPSS 53.33%
- Veröffentlicht 16.07.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:11
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.
CVE-2020-13241
- EPSS 0.05%
- Veröffentlicht 20.05.2020 19:15:09
- Zuletzt bearbeitet 21.11.2024 05:00:51
Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extension (used with the Add Image option on the Edit User screen) corresponds to an image file.
CVE-2018-19917
- EPSS 0.67%
- Veröffentlicht 21.03.2019 16:00:33
- Zuletzt bearbeitet 21.11.2024 03:58:48
Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities.