
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-70791 is a reflected Cross-Site Scripting (XSS) vulnerability in the /admin/order/abandoned endpoint of Microweber, a PHP-based CMS and e-commerce platform. The vulnerability affects Microweber version 2.0.19 and was disclosed on February 5, 2026, with a fix released in version 2.0.20. An unauthenticated attacker can craft a malicious URL targeting the orderDirection parameter and socially engineer an admin user into visiting it, resulting in JavaScript execution in the victim's browser. It carries a CVSS v3.1 base score of 6.1 (Medium) (Github Advisory, Feedly).
The root cause is improper neutralization of user-supplied input (CWE-79): the orderDirection GET parameter in AbandonedOrderController.php was passed directly into the HTTP response without sanitization, allowing injection of arbitrary HTML and JavaScript. The fix applied xss_clean() to the orderDirection, orderBy, priceBetween, and keyword parameters before use, as seen in the patching commit (Microweber Commit). Exploitation requires no authentication or prior privileges on the attacker's part, but does require the victim (an admin) to click a crafted link. A public proof-of-concept demonstrates the attack using the URL-encoded payload "> appended to the orderDirection parameter (PoC Gist).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of an authenticated administrator's browser session. This can lead to theft of admin session tokens, unauthorized administrative actions (such as creating new admin accounts or modifying site content), and access to sensitive data visible within the admin panel. While availability is not directly impacted, the integrity and confidentiality of the Microweber instance and its data are at risk if an admin is successfully targeted (Github Advisory, Feedly).
A public proof-of-concept exploit is available as a GitHub Gist published by researcher Tim Recktenwald, demonstrating a simple alert-based XSS payload (PoC Gist). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.036%, indicating a low near-term exploitation probability (Github Advisory). No threat actor attribution has been reported.
orderDirection parameter, e.g.:http://target.example.com/admin/order/abandoned?orderDirection=%22%3E%3Cscript%3Ealert%281%29%3B%3C%2Fscript%3EorderDirection value is reflected into the HTML response, causing the injected <script> tag to execute in the admin's browser.alert(1) payload with a more sophisticated script to steal the admin's session cookie, exfiltrate data, or perform unauthorized actions (e.g., create a new admin account) using the victim's authenticated session (PoC Gist, Microweber Commit)./admin/order/abandoned containing URL-encoded script tags or JavaScript in the orderDirection parameter (e.g., %3Cscript%3E, %22%3E, javascript:)./admin/order/abandoned?orderDirection= with unusual or encoded characters from external or unexpected IP addresses; admin session activity originating from a different IP than the admin's normal location shortly after such a request.The primary remediation is to upgrade Microweber to version 2.0.20 or later, which applies xss_clean() sanitization to the affected parameters (orderDirection, orderBy, priceBetween, keyword) in the abandoned orders controller (Microweber Commit, Github Advisory). If immediate patching is not feasible, deploy a Web Application Firewall (WAF) rule to block requests containing JavaScript patterns (e.g., <script>, javascript:, event handlers) in the orderDirection parameter. Additionally, restrict admin panel access to trusted IP addresses and educate administrators to avoid clicking unsolicited or suspicious links.
The vulnerability was discovered and reported by researcher Tim Recktenwald, who published a proof-of-concept gist and responsibly disclosed the issue to the Microweber developers prior to public disclosure (PoC Gist). The issue received a brief write-up on Infinitsec.net shortly after disclosure. No significant broader media coverage or notable community debate has been observed for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."