← back
CVE-2022-0963mediumCWE-79

Unrestricted XML Files Leads to Stored XSS in microweber/microweber

28Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 5.7epss 1.9%
exploitation probability
1.9%top 22% of all CVEs
observed exploitation
nono source reports it
Unrestricted XML Files Leads to Stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N