ZeroHour

CVE-2025-60954

PoC ×2
CVSS 3.1
8.3 high
EPSS
<1%p36
Published
()
Modified
Description

Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including administrative accounts.

Vendors
microweber
Products
microweber
Weakness
CWE-521
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.