PT-2022-13509 · Unknown · Microweber

Published

2022-03-10

·

Updated

2023-07-21

·

CVE-2022-0895

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions microweber/microweber versions prior to 1.3
Description The issue concerns static code injection in the microweber/microweber GitHub repository. Microweber is a content management system (CMS) that features drag and drop functionality.
Recommendations For versions prior to 1.3, update to version 1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the CMS to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2022-0895
GHSA-X28W-HVWC-MP75

Affected Products

Microweber