
Cloud Vulnerability DB
A community-led vulnerabilities database
An unrestricted file upload vulnerability leading to stored Cross-Site Scripting (XSS) was discovered in the GitHub repository microweber/microweber versions prior to 1.1.12. The vulnerability was assigned CVE-2022-0906 and was recorded on March 9, 2022 (CVE Details).
The vulnerability is classified under CWE-79 (Cross-site Scripting) and involves unrestricted file upload functionality that could lead to stored XSS attacks. A fix was implemented through a commit that updated the dangerous file extensions list to include 'aspx' files (GitHub Commit).
The vulnerability could allow attackers to execute stored cross-site scripting attacks through unrestricted file uploads, potentially leading to the execution of malicious scripts in users' browsers within the context of the affected site (CVE Details).
The vulnerability was patched in version 1.1.12 of the Microweber software. The fix involved updating the system's file extension filtering to include 'aspx' in the list of dangerous file extensions (GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."