Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execution in the context of authenticated admin users.
| Software | From | Fixed in |
|---|---|---|
microweber / microweber
|
2.0.0 | 2.0.19.x |
| microweber / microweber | 2.0.0 | 2.0.0.x |