CVE-2025-2214
CVSS 3.1 Score 9.1 of 10 (high)
Details
Summary
CVE-2025-2214 is a recently disclosed vulnerability affecting Microweber 2.0.19. The issue lies within the processing of the file userfiles/modules/settings/group/website_group/index.php in the Settings Handler component. An attacker can exploit this cross-site scripting (XSS) vulnerability by manipulating the argument "group," allowing them to inject malicious code. This exploit can be executed remotely, making it a significant security concern. Unfortunately, the vendor has not responded to reports of this vulnerability, leaving users at risk until a patch is released.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Sentry
Affected Vendors
- Functional Software, Inc.