Vulnerability Description
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microweber | Microweber | < 1.3.2 |
Related Weaknesses (CWE)
References
- https://github.com/microweber/microweber/commit/f20abf30a1d9c1426c5fb757ac63998dPatchThird Party Advisory
- https://huntr.dev/bounties/747c2924-95ca-4311-9e69-58ee0fb440a0ExploitIssue TrackingPatch
- https://github.com/microweber/microweber/commit/f20abf30a1d9c1426c5fb757ac63998dPatchThird Party Advisory
- https://huntr.dev/bounties/747c2924-95ca-4311-9e69-58ee0fb440a0ExploitIssue TrackingPatch
FAQ
What is CVE-2022-3245?
CVE-2022-3245 is a vulnerability with a CVSS score of 6.1 (MEDIUM). HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit in...
How severe is CVE-2022-3245?
CVE-2022-3245 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-3245?
Check the references section above for vendor advisories and patch information. Affected products include: Microweber Microweber.