Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods in microweber/microweber
28Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 6.8epss 3.2%
exploitation probability
3.2%top 12% of all CVEs
observed exploitation
nono source reports it
Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods in GitHub repository microweber/microweber prior to 1.2.11.
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Affected products
microweber · microweber/microweber