CVE-2025-70791 UNKNOWN

CVE-2025-70791

Published: 2026-02-05

Description

Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the developers and fixed in version 2.0.20.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…