Vulnerability Description
A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microweber | Microweber | <= 2.0.15 |
Related Weaknesses (CWE)
References
- http://microweber.comProduct
- https://github.com/microweber/microweber/commit/0dede6886c6df3d1f31c4f4e3ba1ab4aPatch
- https://seclists.org/fulldisclosure/2024/Aug/1Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2024/Aug/1
FAQ
What is CVE-2024-40101?
CVE-2024-40101 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keyw...
How severe is CVE-2024-40101?
CVE-2024-40101 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-40101?
Check the references section above for vendor advisories and patch information. Affected products include: Microweber Microweber.