Executive brief
Microweber is a website builder and online shop platform. The administration panel contains a reflected XSS vulnerability in the settings endpoint that allows attackers to inject malicious JavaScript code. An authenticated admin tricked into clicking a malicious link could have their session hijacked, sensitive information stolen, or malicious actions performed on their behalf.
Technical details
A reflected XSS vulnerability exists in the 'group' parameter of the '/admin/settings' endpoint in the Microweber administration panel. The vulnerability requires high-privilege user interaction (authenticated admin must visit a malicious link), but enables session hijacking, credential theft, or unauthorized actions within the administrative interface. No fix has been reported as of the advisory date.
Affected products
- Microweber Microweber v2.0.19
Timeline
- 2026-09-23: disclosed: Published in NVD
- 2026-06-01: advisory: INCIBE-CERT advisory INCIBE-2026-661 published