
Stored Cross Site Scripting vulnerability in Microweber < 2.0.9
Stored Cross Site Scripting vulnerability in Microweber <= 2.0.9
A Stored Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the "Add new campaign" function.
An attacker could execute JavaScript code in the victim's browser, obtaining information or forcing the user to access malicious websites, for example.