Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6339 | Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user. |
Github GHSA |
GHSA-gmh3-x5w7-jg5m | Microweber before v1.2.20 vulnerable to cross-site scripting |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: @huntrdev
Published:
Updated: 2024-08-03T00:32:09.612Z
Reserved: 2022-07-08T00:00:00
Link: CVE-2022-2353
No data.
Status : Modified
Published: 2022-07-09T09:15:08.727
Modified: 2024-11-21T07:00:49.623
Link: CVE-2022-2353
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA