Impact
The vulnerability is a reflected cross‑site scripting flaw in the Microweber administration panel, specifically in the ‘group’ parameter of the ‘/admin/settings’ endpoint. An attacker can craft a URL that contains malicious JavaScript, which, when opened by an authenticated administrator, executes in the user's browser. This permits the attacker to perform privileged actions under the victim’s account, steal sensitive information, or hijack the user session, thereby compromising confidentiality, integrity, and availability of the administration functions.
Affected Systems
Microweber versions identified by the CPE include the Administration panel 2.0.19. The affected component is the web interface’s settings endpoint, and the flaw applies only to users who have successfully authenticated to the admin panel.
Risk and Exploitability
The CVSS score of 5.9 indicates a medium severity vulnerability. No EPSS value is available, and the issue is not listed in the CISA KEV catalog, suggesting it is not a widely exploited or immediately threatening vulnerability, but the potential impact on authenticated users is significant. Attackers could exploit this via a phishing or social engineering vector that directs an administrator to the crafted URL. Because the flaw is only exploited in the context of an authenticated session, the attacker need not bypass authentication but must convince the victim to visit the malicious link.
OpenCVE Enrichment