{"id":"CVE-2022-0906","aliases":["GHSA-hf4q-52x6-4p57"],"url":"https://o3.security/vulnerability/CVE-2022-0906","summary":"Unrestricted file upload leads to stored XSS in microweber/microweber","details":"Unrestricted file upload leads to stored XSS in GitHub repository microweber/microweber prior to 1.1.12.","published":"2022-03-10T14:55:10Z","modified":"2026-08-12T03:51:17.175472042Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"microweber/microweber","fixedVersion":"1.2.12"}],"fix":{"url":"https://github.com/microweber/microweber/commit/d9bae9df873c2d2a13a2eb08d512019d49ebca68","label":"microweber/microweber@d9bae9d"},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/87ed3b42-9824-49b0-91a5-fd908a0601e8"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0906.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0906"},{"type":"FIX","url":"https://github.com/microweber/microweber/commit/d9bae9df873c2d2a13a2eb08d512019d49ebca68"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:17.175472042Z"}}