Medium severity5.4NVD Advisory· Published Nov 8, 2023· Updated Jun 17, 2026
CVE-2023-47379
CVE-2023-47379
Description
Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
microweber/microweberPackagist | < 2.0.3 | 2.0.3 |
Affected products
3- cpe:2.3:a:microweber:microweber:2.0.1:*:*:*:*:*:*:*
- Microweber/CMSdescription
Patches
Vulnerability mechanics
References
7- github.com/microweber/microweber/commit/c6e7ea9d0abd7564a3bb23c14ad172e4ccf27a7envdPatchWEB
- github.com/advisories/GHSA-jmwm-w2rm-prv9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-47379ghsaADVISORY
- www.getastra.com/blog/security-audit/stored-xss-vulnerability/nvdThird Party Advisory
- github.com/microweber/microweber/blob/master/CHANGELOG.mdnvdRelease NotesWEB
- github.com/microweber/microweber/commit/a481f079d74e82f6094abf15d67e814349d1038aghsaWEB
- www.getastra.com/blog/security-audit/stored-xss-vulnerabilityghsaWEB
News mentions
0No linked articles in our index yet.