Security Advisory

CVE-2025-51502

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-08-01 00:00:00
Last updated 2025-08-01 18:01:25
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execution in the context of authenticated admin users.