Stored Cross-Site Scripting Vulnerability in Subrion CMS by Intelliants
CVE-2021-41502
5.4MEDIUM
What is CVE-2021-41502?
A stored cross-site scripting (XSS) vulnerability exists in Subrion CMS version 4.2.1, which allows attackers to execute arbitrary JavaScript code. This can be exploited by malicious users who manipulate the name of an uploaded image, either closing an HTML tag prematurely or including an 'onerror' attribute. This vulnerability can lead to unauthorized actions and could compromise user sessions, making it essential for administrators to patch their systems promptly.