CVE-2024-58289

Source
https://cve.org/CVERecord?id=CVE-2024-58289
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58289.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-58289
Published
2025-12-11T21:34:21.705Z
Modified
2026-08-12T03:51:13.338452599Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Microweber 2.0.15 Stored Cross-Site Scripting via User Profile Fields
Details

Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Attackers can input script payloads in the first name field that will execute when the profile is viewed by other users, potentially stealing session cookies and executing arbitrary JavaScript.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/58xxx/CVE-2024-58289.json",
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/microweber/microweber

Affected ranges

Type
GIT
Repo
https://github.com/microweber/microweber
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:microweber:microweber:2.0.15:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.0.15"
        },
        {
            "last_affected": "2.0.15"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_STRING"
    ]
}

Affected versions

2.*
2.0.15
v2.*
v2.0.15

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58289.json"