MEDIUM
Code Injection in display of tag title on saving tags in microweber/microweber
Published Sep 20, 2022
6.1
MEDIUMCVSS 3.1
EPSS 0.72%
Description
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<1.3.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Microweber | Microweber/microweber | n/a |
|
- < 1.3.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6825 Advisory
- https://github.com/advisories/GHSA-gm8c-w9cm-c445 Advisory
- https://github.com/microweber/microweber/commit/f20abf30a1d9c1426c5fb757ac63998dc5b92bfc x_refsource_MISCPatchThird Party Advisory
- https://huntr.dev/bounties/747c2924-95ca-4311-9e69-58ee0fb440a0 x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3245
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6825 | Advisory | |
| https://github.com/advisories/GHSA-gm8c-w9cm-c445 | Advisory | |
| https://github.com/microweber/microweber/commit/f20abf30a1d9c1426c5fb757ac63998dc5b92bfc | x_refsource_MISCPatchThird Party Advisory | |
| https://huntr.dev/bounties/747c2924-95ca-4311-9e69-58ee0fb440a0 | x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3245 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published Sep 20, 2022
Updated May 27, 2025
Reserved Sep 20, 2022
Link CVE-2022-3245
CISA Vulnrichment
Updated May 27, 2025
ENISA EUVD
EUVD-2022-6825 GHSA-GM8C-W9CM-C445 Assigner @huntrdev
Published Sep 20, 2022
Updated May 27, 2025
Exploited since n/a
Link EUVD-2022-6825