A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leading to arbitrary JavaScript execution in admin browsers.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://github.com/progprnv/CVE-Reports | Third Party Advisory |
https://github.com/progprnv/CVE-Reports/blob/main/CVE-2025-51503 | Third Party Advisory |
https://github.com/progprnv/CVE-Reports/blob/main/MICROWEBER%20%5BAdmin%20Panel%5D%20Stored%20XSS%20in%20profile%20path.md | Broken Link |
Configurations
History
06 Aug 2025, 16:21
Type | Values Removed | Values Added |
---|---|---|
First Time |
Microweber microweber
Microweber |
|
CPE | cpe:2.3:a:microweber:microweber:2.0.0:*:*:*:*:*:*:* | |
References | () https://github.com/progprnv/CVE-Reports/blob/main/CVE-2025-51503 - Third Party Advisory | |
References | () https://github.com/progprnv/CVE-Reports - Third Party Advisory | |
References | () https://github.com/progprnv/CVE-Reports/blob/main/MICROWEBER%20%5BAdmin%20Panel%5D%20Stored%20XSS%20in%20profile%20path.md - Broken Link |
31 Jul 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-31 18:15
Updated : 2025-08-06 16:21
NVD link : CVE-2025-51503
Mitre link : CVE-2025-51503
JSON object : View
Products Affected
microweber
- microweber
CWE
No CWE.