Stored Cross-Site Scripting Vulnerability in Subrion CMS by Intelliants
CVE-2021-41502

5.4MEDIUM

Key Information:

Vendor
CVE Published:
11 June 2022

What is CVE-2021-41502?

A stored cross-site scripting (XSS) vulnerability exists in Subrion CMS version 4.2.1, which allows attackers to execute arbitrary JavaScript code. This can be exploited by malicious users who manipulate the name of an uploaded image, either closing an HTML tag prematurely or including an 'onerror' attribute. This vulnerability can lead to unauthorized actions and could compromise user sessions, making it essential for administrators to patch their systems promptly.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.