S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0378 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in microweber/microweber affects v. before 1.2.11.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0378
5.4
CVSShigh
Exploitable remotely over the internet · no authentication required · user interaction needed.

Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
microweber/microweberby microweber
AFFECTED< 1.2.11SAFE ✓≥ 1.2.11
Updated Aug 22, 2026View on NVD →
Detail

Microweber/Microweber is an open-source website-builder and CMS designed to make it easy for non-technical users to create responsive websites and online stores. It is a popular choice for small businesses, freelancers, and content creators who want a simple, yet powerful platform that can help them get online quickly and easily. With a user-friendly interface and a large selection of customizable templates, Microweber/Microweber is a great option for anyone who wants to make a professional-looking website without a lot of technical know-how.

One of the most critical vulnerabilities that have been identified in this software is the CVE-2022-0378 vulnerability. This vulnerability is classified as a cross-site scripting (XSS) vulnerability and affects versions of Microweber/Microweber prior to version 1.2.11. When exploited, this vulnerability can allow an attacker to inject malicious code into a user's browser, potentially stealing sensitive information or installing malware onto the user's device.

If this vulnerability is exploited, it can lead to some devastating consequences. An attacker can use it to gain access to sensitive information, such as login credentials, personal information, and financial data, or they may install malware onto the user's device or network. Furthermore, it can result in a loss of reputational damage to the affected entities and financial implications.

By leveraging the pro features of s4e.io, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. With advanced scanning tools and real-time threat alerts, the platform is a powerhouse when it comes to identifying and mitigating potential threats to businesses of all sizes. As a result, companies can be proactive in addressing vulnerabilities and keeping their systems secure, which means more peace of mind and less risk across the board.

 

REFERENCES

Solution Advice

Fortunately, there are several precautions that can be taken to protect against this vulnerability. These include:

  • Ensuring that Microweber/Microweber is updated to the latest version
  • Disabling any unnecessary plugins or extensions
  • Implementing content security policies (CSPs) that limit the types of content that can be executed on a user's browser
  • Educating users on how to identify and report suspicious activity on their websites and networks

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-0378 scanner - Cross-Site Scripting (XSS) vulnerability in microweber/microweber S4E