Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-70792

Опубликовано: 05 фев. 2026
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20.

EPSS

Процентиль: 10%
0.00036
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
github
2 дня назад

Microweber Cross-site Scripting vulnerability

EPSS

Процентиль: 10%
0.00036
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79