Microweber

Microweber

118 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.08%
  • Veröffentlicht 11.07.2022 08:15:07
  • Zuletzt bearbeitet 25.02.2026 15:18:42

Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.

Exploit
  • EPSS 0.51%
  • Veröffentlicht 09.07.2022 09:15:08
  • Zuletzt bearbeitet 21.11.2024 07:00:49

Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user.

Exploit
  • EPSS 0.51%
  • Veröffentlicht 04.07.2022 11:15:13
  • Zuletzt bearbeitet 21.11.2024 07:00:43

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.

Exploit
  • EPSS 0.57%
  • Veröffentlicht 01.07.2022 09:15:09
  • Zuletzt bearbeitet 21.11.2024 07:00:40

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.

Exploit
  • EPSS 0.89%
  • Veröffentlicht 29.06.2022 16:15:07
  • Zuletzt bearbeitet 21.11.2024 07:00:37

Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.

Exploit
  • EPSS 3%
  • Veröffentlicht 22.06.2022 12:15:08
  • Zuletzt bearbeitet 21.11.2024 07:00:28

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.

Exploit
  • EPSS 3.08%
  • Veröffentlicht 20.06.2022 09:15:08
  • Zuletzt bearbeitet 21.11.2024 07:00:22

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17.

Exploit
  • EPSS 8.85%
  • Veröffentlicht 09.05.2022 14:15:08
  • Zuletzt bearbeitet 21.11.2024 06:41:08

Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account in the application using the V...

Exploit
  • EPSS 0.84%
  • Veröffentlicht 04.05.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:41:01

Reflected XSS in GitHub repository microweber/microweber prior to 1.2.16. Executing JavaScript as the victim

Exploit
  • EPSS 1.24%
  • Veröffentlicht 04.05.2022 09:15:08
  • Zuletzt bearbeitet 21.11.2024 06:40:57

DOM XSS in microweber ver 1.2.15 in GitHub repository microweber/microweber prior to 1.2.16. inject arbitrary js code, deface website, steal cookie...