CVE-2022-1504
- EPSS 0.97%
- Veröffentlicht 27.04.2022 11:15:44
- Zuletzt bearbeitet 21.11.2024 06:40:51
XSS in /demo/module/?module=HERE in GitHub repository microweber/microweber prior to 1.2.15. Typical impact of XSS attacks.
CVE-2022-1439
- EPSS 3.26%
- Veröffentlicht 22.04.2022 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:40:44
Reflected XSS on demo.microweber.org/demo/module/ in GitHub repository microweber/microweber prior to 1.2.15. Execute Arbitrary JavaScript as the attacked user. It's the only payload I found working, you might need to press "tab" but there is probabl...
CVE-2022-1036
- EPSS 1.23%
- Veröffentlicht 22.03.2022 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:39:54
Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12.
CVE-2022-0968
- EPSS 3.73%
- Veröffentlicht 15.03.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:39:45
The microweber application allows large characters to insert in the input field "fist & last name" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in microweber/microweber in GitHub repository microweber/micro...
CVE-2022-0963
- EPSS 1.88%
- Veröffentlicht 15.03.2022 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:39:45
Unrestricted XML Files Leads to Stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
CVE-2022-0961
- EPSS 1.01%
- Veröffentlicht 15.03.2022 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:39:45
The microweber application allows large characters to insert in the input field "post title" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in GitHub repository microweber/microweber prior to 1.2.12.
CVE-2022-0954
- EPSS 3.2%
- Veröffentlicht 15.03.2022 12:15:10
- Zuletzt bearbeitet 21.11.2024 06:39:44
Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods in GitHub repository microweber/microweber prior to 1.2.11.
CVE-2022-0930
- EPSS 0.91%
- Veröffentlicht 12.03.2022 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:39:41
File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
CVE-2022-0929
- EPSS 1.08%
- Veröffentlicht 12.03.2022 11:15:08
- Zuletzt bearbeitet 21.11.2024 06:39:41
XSS on dynamic_text module in GitHub repository microweber/microweber prior to 1.2.11.
CVE-2022-0926
- EPSS 0.79%
- Veröffentlicht 12.03.2022 10:15:08
- Zuletzt bearbeitet 21.11.2024 06:39:40
File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.