Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last name field.
| Software | From | Fixed in |
|---|---|---|
microweber / microweber
|
2.0.0 | 2.0.19.x |
| microweber / microweber | 2.0.0 | 2.0.0.x |