Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbitrary JavaScript.
| Software | From | Fixed in |
|---|---|---|
microweber / microweber
|
2.0.0 | 2.0.19.x |
| microweber / microweber | 2.0.0 | 2.0.0.x |