CVE-2022-3242 is a code injection vulnerability affecting Microweber versions prior to 1.3.2, also categorized as Cross-Site Scripting (CWE-79) and Code Injection (CWE-94). With a CVSS score of 6.1 (MEDIUM), it can be exploited remotely with low attack complexity, requiring user interaction, potentially leading to limited confidentiality and integrity impacts. While the vulnerability has a high FAUCET Risk Score of 92/100 and a higher EPSS score than 0.945% of all CVEs, there is no evidence of active exploitation, Metasploit modules, or ExploitDB entries. Community discussion and media coverage are minimal, though Nuclei templates exist for detecting the associated XSS.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.2CPE matchmatch criteria | cpe:2.3:a:microweber:microweber:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.