Vulnerabilidades en Microweber

86 resultados
Análisis Vexday

O Microweber apresenta 2 vulnerabilidades catalogadas, ambas publicadas nos últimos 90 dias, sem registros de exploração ativa (KEV) até o momento. A fraqueza dominante é CWE-434 (upload de arquivo restrito inadequadamente), um vetor clássico de comprometimento, mas a ausência de críticas e atividade explorada em campo sugere risco moderado e controlável com patching oportuno.

CVE-2022-0895HIGHStatic Code Injection in microweber/microweberEPSS 1.7%CVE-2022-0913CRITICALInteger Overflow or Wraparound in microweber/microweberEPSS 1.4%CVE-2022-0896HIGHImproper Neutralization of Special Elements Used in a Template Engine in microweber/microweberEPSS 1.4%CVE-2022-0721HIGHInsertion of Sensitive Information Into Debugging Code in microweber/microweberEPSS 1.4%CVE-2022-0282MEDIUMCross-site Scripting in microweber/microweberEPSS 1.4%CVE-2022-0724CRITICALInsecure Storage of Sensitive Information in microweber/microweberEPSS 1.3%CVE-2022-0777HIGHWeak Password Recovery Mechanism for Forgotten Password in microweber/microweberEPSS 1.2%CVE-2022-1555HIGHDOM XSS in microweber ver 1.2.15 in microweber/microweberEPSS 1.2%CVE-2022-1036MEDIUMAble to create an account with long password leads to memory corruption / Integer Overflow in microweber/microweberEPSS 1.2%CVE-2022-0504MEDIUMGeneration of Error Message Containing Sensitive Information in microweber/microweberEPSS 1.2%CVE-2022-0277MEDIUMIncorrect Permission Assignment for Critical Resource in microweber/microweberEPSS 1.1%CVE-2022-0690HIGHCross-site Scripting (XSS) - Reflected in microweber/microweberEPSS 1.1%CVE-2022-2368MEDIUMAuthentication Bypass by Spoofing in microweber/microweberEPSS 1.1%CVE-2022-0929MEDIUMXSS on dynamic_text module in microweber/microweberEPSS 1.1%CVE-2023-5244MEDIUMCross-site Scripting (XSS) - Reflected in microweber/microweberEPSS 1.1%CVE-2022-0689MEDIUMUse multiple time the one-time coupon in microweber/microweberEPSS 1.0%CVE-2022-0560MEDIUMOpen Redirect in microweber/microweberEPSS 1.0%CVE-2022-0961HIGHThe microweber application allows large characters to insert in the input field "post title" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in microweber/microweberEPSS 1.0%CVE-2022-1504MEDIUMXSS in /demo/module/?module=HERE in microweber/microweberEPSS 1.0%CVE-2022-2470MEDIUMCross-site Scripting (XSS) - Reflected in microweber/microweberEPSS 1.0%