Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Attackers can input script payloads in the first name field that will execute when the profile is viewed by other users, potentially stealing session cookies and executing arbitrary JavaScript.
History

Fri, 12 Dec 2025 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Microweber
Microweber microweber
Vendors & Products Microweber
Microweber microweber

Thu, 11 Dec 2025 21:45:00 +0000

Type Values Removed Values Added
Description Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Attackers can input script payloads in the first name field that will execute when the profile is viewed by other users, potentially stealing session cookies and executing arbitrary JavaScript.
Title Microweber 2.0.15 Stored Cross-Site Scripting via User Profile Fields
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-11T21:34:21.705Z

Updated: 2025-12-11T21:34:21.705Z

Reserved: 2025-12-10T23:46:14.009Z

Link: CVE-2024-58289

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-11T22:15:49.557

Modified: 2025-12-12T15:17:31.973

Link: CVE-2024-58289

cve-icon Redhat

No data.