S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0963 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in microweber/microweber affects v. before 1.2.12.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.3k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0963
5.4
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient · user interaction needed.

Unrestricted XML Files Leads to Stored XSS in GitHub repository microweber/microweber prior to 1.2.12.

Attack Vector
Network
Privileges Req.
Low
User Interaction
Required
Affected
microweber/microweberby microweber
AFFECTED< 1.2.12SAFE ✓≥ 1.2.12
Updated Aug 22, 2026View on NVD →
Detail

Microweber/Microweber is an open-source CMS (Content Management System) software used to create websites, online stores, and blogs. It allows users to create and manage their digital content without any technical knowledge. Microweber/Microweber offers pre-designed templates and modules to facilitate the website creation process.

The CVE-2022-0963 vulnerability in Microweber/Microweber was detected, which concerns unrestricted XML files that can lead to Stored XSS (Cross-Site Scripting). Essentially, the vulnerability allows an attacker to inject malicious code into a website, which can then be executed on the website visitor's browser. 

When exploited, this vulnerability can lead to severe consequences for websites. Attackers can steal user information, cause website defacement, or even perform client-side attacks that redirect users to phishing sites or install malware on their devices. Microweber/Microweber users are therefore encouraged to update their software to version 1.2.12 or above to prevent such attacks.

Users who are concerned about vulnerabilities in their digital assets can easily and quickly learn more thanks to the pro features offered by s4e.io. This platform provides comprehensive reports that explain vulnerabilities, suggest remediation strategies, and continuously monitor the website for any security breaches. With their help, Microweber/Microweber users can ensure their websites are secure and protected from potential attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Upgrade to the latest version of Microweber/Microweber
  • Deploy web application firewalls to filter malicious requests
  • Use Content Security Policy (CSP) headers to restrict the execution of external scripts
  • Sanitize user input data and validate all XML files uploaded to the system
  • Implement security testing tools for regular website vulnerability assessments

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-0963 scanner - Cross-Site Scripting (XSS) vulnerability in microweber/microweber | S4E