Loading HuntDB...

GHSA-hhjm-mpmf-cxg9

GitHub Security Advisory

Microweber vulnerable to stored cross-site scripting (XSS) via X-Forwarded-For header

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

microweber/microweber prior to 1.3.3 is vulnerable to stored cross-site scripting (XSS) via the `X-Forwarded-For` header. This was fixed in version 1.3.3.

Affected Packages

Packagist microweber/microweber
Affected versions: 0 (fixed in 1.3.3)

Related CVEs

Key Information

GHSA ID
GHSA-hhjm-mpmf-cxg9
Published
April 5, 2023 6:30 PM
Last Modified
April 6, 2023 4:54 PM
CVSS Score
7.5 /10
Primary Ecosystem
Packagist
Primary Package
microweber/microweber
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 2, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.