S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-2174 Scanner

Detects 'Cross-Site Scripting' vulnerability in microweber affects versions prior to 1.2.18

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-2174
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required.

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
microweber/microweberby microweber
AFFECTED< 1.2.18SAFE ✓≥ 1.2.18
Updated Aug 22, 2026View on NVD →
Detail

Microweber is an open-source content management system and website builder. It is designed to allow individuals and businesses to easily create websites and online stores without the need for coding knowledge. The platform utilizes a drag-and-drop interface, making it accessible to users of all skill levels. Microweber is built on top of the Laravel PHP framework, ensuring a robust and secure foundation for websites. It's popular among small to medium-sized businesses for its ease of use, flexibility, and comprehensive e-commerce solutions.

The vulnerability specifically exists due to improper handling of user input in the type parameter of the /api/module endpoint. By crafting a request that includes a malicious script in the type parameter, an attacker can execute arbitrary JavaScript code in the browser of any user who accesses the crafted URL. The absence of proper sanitization and output encoding makes the application vulnerable to XSS, where the attacker's code can run under the guise of the legitimate site.

The exploitation of this XSS vulnerability can lead to various adverse effects, including but not limited to, session hijacking, phishing attacks, redirection to malicious sites, and unauthorized access to sensitive information. It undermines the integrity and confidentiality of user sessions and can damage the reputation of businesses utilizing the Microweber platform for their websites or online stores.

S4E provides a robust platform for detecting and managing vulnerabilities like CVE-2022-2174 in Microweber and other digital assets. By becoming a member, users benefit from comprehensive security scans, real-time alerts, and expert recommendations to address vulnerabilities effectively. Our service enhances your cybersecurity posture, helping to protect your website against attacks and ensuring the safety of your data and your users' information.

 

References

Solution Advice
  1. Update Microweber to version 1.2.18 or later to mitigate the XSS vulnerability.
  2. Implement content security policies (CSP) to reduce the risk of XSS attacks.
  3. Regularly review and sanitize all user inputs and outputs within the application to prevent injection attacks.
  4. Educate users and administrators about the risks associated with clicking on unknown or suspicious links.
  5. Perform regular security audits and penetration testing to identify and address new vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.