S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0954 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in microweber/microweber affects v. prior to 1.2.11.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
3.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0954
5.4
CVSSmedium
Exploitable remotely over the internet · requires high privileges · user interaction needed.

Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods in GitHub repository microweber/microweber prior to 1.2.11.

Attack Vector
Network
Privileges Req.
High
User Interaction
Required
Affected
microweber/microweberby microweber
AFFECTED< 1.2.11SAFE ✓≥ 1.2.11
Updated Aug 22, 2026View on NVD →
Detail

Microweber/Microweber is a popular content management system that has been widely used in building websites and e-commerce platforms. It is a multifunctional system that provides users with a wide range of features to customize and manage their websites efficiently. The product is designed to simplify the process of creating and managing websites, and it offers a user-friendly interface to help beginners as well as professionals.

Recently, a critical vulnerability (CVE-2022-0954) has been discovered in the Microweber/Microweber prior to version 1.2.11. The vulnerability is a cross-site scripting (XSS) vulnerability that can be exploited by attackers to inject malicious code into the website's other settings, autorespond email settings, and payment methods sections. By exploiting this vulnerability, attackers can gain access to sensitive information such as user credentials, payment information, and confidential emails.

This vulnerability can lead to disastrous consequences for users and their websites. If an attacker exploits this vulnerability, they can inject malicious code into the website that can redirect users to phishing websites, steal sensitive information, spread malware, and perform other malicious activities. Moreover, the vulnerability can compromise the website's reputation and cause a decline in trust among the website's users.

Thanks to the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. The platform offers a comprehensive vulnerability assessment service that can detect and prioritize vulnerabilities in websites and web applications. It also provides actionable recommendations to fix vulnerabilities and secure digital assets. By using such platforms, website owners can significantly reduce the risk of cyber attacks and protect their digital assets from becoming compromised.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Upgrade to the latest version of Microweber/Microweber (version 1.2.11 or higher).
  • Install and activate a reputable web application firewall (WAF) that can detect and block XSS attacks.
  • Review and strengthen the website's access control policies to prevent unauthorized access.
  • Educate website administrators and users on the importance of safe browsing habits and password management.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.