← back
CVE-2022-0928mediumCWE-79

Cross-site Scripting (XSS) - Stored in microweber/microweber

28Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 6.8epss 2.4%
exploitation probability
2.4%top 17% of all CVEs
observed exploitation
nono source reports it
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.12.
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H