Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-33298

EPSS 1.30% · P80
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-33298

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microweber 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microweber是Microweber开源的一套可提供拖拽功能的网上商店管理系统。该系统包括添加商品、图片等模块。 Microweber v.2.0.9版本存在安全漏洞,该漏洞源于存在跨站脚本漏洞,允许远程攻击者通过端点/admin/module/view?type=admin__backup中的创建新备份功能执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2024-33298

#POC DescriptionSource LinkShenlong Link
1Stored Cross Site Scripting vulnerability in Microweber < 2.0.9https://github.com/MathSabo/CVE-2024-33298POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-33298

登录查看更多情报信息。

Same Patch Batch · n/a · 2025-01-10 · 33 CVEs total

CVE-2024-29970Fortanix Enclave OS 安全漏洞
CVE-2024-46210REDAXO 安全漏洞
CVE-2024-33297Microweber 安全漏洞
CVE-2024-33299Microweber 安全漏洞
CVE-2024-54994MonicaHQ 安全漏洞
CVE-2024-54849CP Plus CP-VNR-3104 安全漏洞
CVE-2024-54848CP Plus CP-VNR-3104 安全漏洞
CVE-2024-54687Vtiger CRM 安全漏洞
CVE-2024-54846CP Plus CP-VNR-3104 安全漏洞
CVE-2024-54996MonicaHQ 安全漏洞
CVE-2024-54998MonicaHQ 安全漏洞
CVE-2024-54997MonicaHQ 安全漏洞
CVE-2024-54910Hasleo Backup Suite Free 安全漏洞
CVE-2024-54847CP Plus CP-VNR-3104 安全漏洞
CVE-2024-25371Gramine 安全漏洞
CVE-2024-50807Responsive FileManager 安全漏洞
CVE-2025-22946Tenda AC9 安全漏洞
CVE-2024-29971Scontain SCONE 安全漏洞
CVE-2024-57687PHPGurukul Land Record System 安全漏洞
CVE-2024-57228Linksys E7350 安全漏洞

Showing top 20 of 33 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-33298

No comments yet


Leave a comment