Security Advisory

CVE-2025-70792

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-02-05 00:00:00
Last updated 2026-02-05 20:50:03
Assigner mitre
State PUBLISHED

Description

Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victims browser. The issue was reported to the developers and fixed in version 2.0.20.