CVE-2025-2214

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Mar 12, 2025
CWE ID 287

Summary

CVE-2025-2214 is a recently disclosed vulnerability affecting Microweber 2.0.19. The issue lies within the processing of the file userfiles/modules/settings/group/website_group/index.php in the Settings Handler component. An attacker can exploit this cross-site scripting (XSS) vulnerability by manipulating the argument "group," allowing them to inject malicious code. This exploit can be executed remotely, making it a significant security concern. Unfortunately, the vendor has not responded to reports of this vulnerability, leaving users at risk until a patch is released.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Sentry

Affected Vendors

  • Functional Software, Inc.