Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-05T16:55:10.348Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-70792
No data.
Status : Received
Published: 2026-02-05T17:16:13.103
Modified: 2026-02-05T17:16:13.103
Link: CVE-2025-70792
No data.
OpenCVE Enrichment
No data.