Moderate severityNVD Advisory· Published Nov 8, 2023· Updated Sep 3, 2024
CVE-2023-47379
CVE-2023-47379
Description
Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
microweber/microweberPackagist | < 2.0.3 | 2.0.3 |
Affected products
2- Microweber/CMSdescription
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-jmwm-w2rm-prv9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-47379ghsaADVISORY
- github.com/microweber/microweber/blob/master/CHANGELOG.mdghsaWEB
- github.com/microweber/microweber/commit/a481f079d74e82f6094abf15d67e814349d1038aghsaWEB
- github.com/microweber/microweber/commit/c6e7ea9d0abd7564a3bb23c14ad172e4ccf27a7eghsaWEB
- www.getastra.com/blog/security-audit/stored-xss-vulnerabilityghsaWEB
- www.getastra.com/blog/security-audit/stored-xss-vulnerability/mitre
News mentions
0No linked articles in our index yet.