Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality.
| Software | From | Fixed in |
|---|---|---|
microweber / microweber
|
- | 2.0.3 |
| microweber / microweber | 2.0.1 | 2.0.1.x |