PT-2025-43670 · Unknown · Microweber Cms

Published

2025-10-24

·

Updated

2025-10-28

·

CVE-2025-60954

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Microweber CMS version 2.0
Description The application does not enforce minimum password length or complexity during password resets. This allows users to set weak passwords, including single-character passwords, potentially leading to account compromise, including administrative accounts.
Recommendations Apply a strong password policy that enforces minimum length and complexity requirements for all user accounts.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-60954

Affected Products

Microweber Cms