CVE-2022-0896 – Improper Neutralization of Special Elements Used in a Template Engine in microweber/microweber
https://notcve.org/view.php?id=CVE-2022-0896
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior to 1.3. Una Neutralización Inapropiada de Elementos Especiales Usados en un Motor de Plantillas en el repositorio de GitHub microweber/microweber versiones anteriores a 1.3 • https://github.com/microweber/microweber/commit/e0224462b3dd6b1f7c6ec1197413afc6019bc3b5 https://huntr.dev/bounties/113056f1-7a78-4205-9f42-940ad41d8df0 • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine •
CVE-2022-0777 – Weak Password Recovery Mechanism for Forgotten Password in microweber/microweber
https://notcve.org/view.php?id=CVE-2022-0777
Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3. Un Mecanismo de Recuperación de Contraseñas Débil para el Olvido de Contraseñas en el repositorio de GitHub microweber/microweber versiones anteriores a 1.3. • https://github.com/microweber/microweber/commit/a3944cf9d1d8c41a48297ddc98302934e2511b0f https://huntr.dev/bounties/b36be8cd-544f-42bd-990d-aa1a46df44d7 • CWE-640: Weak Password Recovery Mechanism for Forgotten Password •
CVE-2022-0723 – Cross-site Scripting (XSS) - Reflected in microweber/microweber
https://notcve.org/view.php?id=CVE-2022-0723
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.11. Una vulnerabilidad de tipo Cross-site Scripting (XSS) - Reflejado en el repositorio de GitHub microweber/microweber versiones anteriores a 1.2.11. • https://github.com/microweber/microweber/commit/15e519a86e4b24526abaf9e6dc81cb1af86843a5 https://huntr.dev/bounties/16b0547b-1bb3-493c-8a00-5b6a11fca1c5 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-0763 – Cross-site Scripting (XSS) - Stored in microweber/microweber
https://notcve.org/view.php?id=CVE-2022-0763
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3. Una vulnerabilidad de tipo Cross-site Scripting (XSS) - Almacenado en el repositorio de GitHub microweber/microweber versiones anteriores a 1.3. • https://github.com/microweber/microweber/commit/c897d0dc159849763a813184d9b75b966c6360bf https://huntr.dev/bounties/6de9c621-740d-4d7a-9d77-d90c6c87f3b6 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-0762 – Incorrect Authorization in microweber/microweber
https://notcve.org/view.php?id=CVE-2022-0762
Incorrect Authorization in GitHub repository microweber/microweber prior to 1.3. Unos Errores de Lógica Empresarial en el repositorio de GitHub microweber/microweber versiones anteriores a 1.3. • https://github.com/microweber/microweber/commit/76361264d9fdfff38a1af79c63141455cc4d36e3 https://huntr.dev/bounties/125b5244-5099-485e-bf75-e5f1ed80dd48 • CWE-863: Incorrect Authorization •