CVE-2025-70791: 
PHP vulnerability analysis and mitigation

Overview

CVE-2025-70791 is a reflected Cross-Site Scripting (XSS) vulnerability in the /admin/order/abandoned endpoint of Microweber, a PHP-based CMS and e-commerce platform. The vulnerability affects Microweber version 2.0.19 and was disclosed on February 5, 2026, with a fix released in version 2.0.20. An unauthenticated attacker can craft a malicious URL targeting the orderDirection parameter and socially engineer an admin user into visiting it, resulting in JavaScript execution in the victim's browser. It carries a CVSS v3.1 base score of 6.1 (Medium) (Github Advisory, Feedly).

Technical details

The root cause is improper neutralization of user-supplied input (CWE-79): the orderDirection GET parameter in AbandonedOrderController.php was passed directly into the HTTP response without sanitization, allowing injection of arbitrary HTML and JavaScript. The fix applied xss_clean() to the orderDirection, orderBy, priceBetween, and keyword parameters before use, as seen in the patching commit (Microweber Commit). Exploitation requires no authentication or prior privileges on the attacker's part, but does require the victim (an admin) to click a crafted link. A public proof-of-concept demonstrates the attack using the URL-encoded payload "> appended to the orderDirection parameter (PoC Gist).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of an authenticated administrator's browser session. This can lead to theft of admin session tokens, unauthorized administrative actions (such as creating new admin accounts or modifying site content), and access to sensitive data visible within the admin panel. While availability is not directly impacted, the integrity and confidentiality of the Microweber instance and its data are at risk if an admin is successfully targeted (Github Advisory, Feedly).

Exploitability

A public proof-of-concept exploit is available as a GitHub Gist published by researcher Tim Recktenwald, demonstrating a simple alert-based XSS payload (PoC Gist). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.036%, indicating a low near-term exploitation probability (Github Advisory). No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify Microweber instances running version 2.0.19 using web search, Shodan, or Censys by fingerprinting the CMS (e.g., via HTTP headers, page metadata, or known URL patterns).
  2. Craft malicious URL: Construct a URL targeting the vulnerable endpoint with a JavaScript payload injected into the orderDirection parameter, e.g.:
    http://target.example.com/admin/order/abandoned?orderDirection=%22%3E%3Cscript%3Ealert%281%29%3B%3C%2Fscript%3E
  3. Social engineering: Deliver the crafted URL to a Microweber administrator via phishing email, chat message, or other social vector, disguising it as a legitimate admin link.
  4. Trigger execution: When the admin visits the URL while authenticated, the unsanitized orderDirection value is reflected into the HTML response, causing the injected <script> tag to execute in the admin's browser.
  5. Achieve objective: Replace the alert(1) payload with a more sophisticated script to steal the admin's session cookie, exfiltrate data, or perform unauthorized actions (e.g., create a new admin account) using the victim's authenticated session (PoC Gist, Microweber Commit).

Indicators of compromise

  • Network: HTTP GET requests to /admin/order/abandoned containing URL-encoded script tags or JavaScript in the orderDirection parameter (e.g., %3Cscript%3E, %22%3E, javascript:).
  • Logs: Web server access logs showing requests to /admin/order/abandoned?orderDirection= with unusual or encoded characters from external or unexpected IP addresses; admin session activity originating from a different IP than the admin's normal location shortly after such a request.
  • Logs: Application logs showing admin-level actions (account creation, content modification, settings changes) immediately following a suspicious request to the abandoned orders endpoint.
  • Network: Outbound connections from the admin's browser to attacker-controlled domains (e.g., for cookie exfiltration) triggered during an admin session on the Microweber admin panel.

Mitigation and workarounds

The primary remediation is to upgrade Microweber to version 2.0.20 or later, which applies xss_clean() sanitization to the affected parameters (orderDirection, orderBy, priceBetween, keyword) in the abandoned orders controller (Microweber Commit, Github Advisory). If immediate patching is not feasible, deploy a Web Application Firewall (WAF) rule to block requests containing JavaScript patterns (e.g., <script>, javascript:, event handlers) in the orderDirection parameter. Additionally, restrict admin panel access to trusted IP addresses and educate administrators to avoid clicking unsolicited or suspicious links.

Community reactions

The vulnerability was discovered and reported by researcher Tim Recktenwald, who published a proof-of-concept gist and responsibly disclosed the issue to the Microweber developers prior to public disclosure (PoC Gist). The issue received a brief write-up on Infinitsec.net shortly after disclosure. No significant broader media coverage or notable community debate has been observed for this vulnerability.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management