MathSabo

3 exploits Active since Jan 2025
CVE-2024-33297 NOMISEC MEDIUM WRITEUP
Microweber < 2.0.9 - XSS
Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add new campaign function
CVSS 4.7
CVE-2024-33298 NOMISEC MEDIUM WRITEUP
Microweber < 2.0.9 - XSS
Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup
CVSS 6.1
CVE-2024-33299 NOMISEC MEDIUM WRITEUP
Microweber < 2.0.9 - XSS
Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the endpoint /admin/module/view?type=users
CVSS 4.7