HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input.
References
| Link | Resource |
|---|---|
| https://github.com/microweber/microweber/commit/f20abf30a1d9c1426c5fb757ac63998dc5b92bfc | Patch Third Party Advisory |
| https://huntr.dev/bounties/747c2924-95ca-4311-9e69-58ee0fb440a0 | Exploit Issue Tracking Patch Third Party Advisory |
Configurations
Information
Published : 2022-09-20 07:15
Updated : 2022-09-21 17:12
NVD link : CVE-2022-3245
Mitre link : CVE-2022-3245
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
microweber
- microweber


