Cross-site Scripting (XSS) - Reflected in microweber/microweber
Feb 18th 2022
Can escape the
meta tag because the user doesn't escape the double-quote in the
$redirectUrl parameter when logging out.
Proof of Concept
Through this vulnerability, an attacker is capable to execute malicious scripts.
Bozhidar Slaveykov Bozhidar
commented a year ago
Peter Ivanov validated this vulnerability a year ago
Pocas has been awarded the disclosure bounty
The fix bounty is now up for grabs
Peter Ivanov marked this as fixed in 1.2.11 with commit 2b8fa5 a year ago
This vulnerability will not receive a CVE
to join this conversation