CVE-2023-47379
Summary
| CVE | CVE-2023-47379 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-11-08 17:15:00 UTC |
| Updated | 2023-11-15 20:12:00 UTC |
| Description | Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Stored XSS Vulnerability in Microweber Version 2.0.1 - Astra |
|
www.getastra.com |
|
| Merge branch 'dev' of github.com:microweber/microweber into dev · microweber/microweber@c6e7ea9 · GitHub |
|
github.com |
|
| microweber/CHANGELOG.md at master · microweber/microweber · GitHub |
|
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995847 PHP (Composer) Security Update for microweber/microweber (GHSA-jmwm-w2rm-prv9)