Cross Site Scripting Vulnerability in Subrion CMS Admin Panel
CVE-2022-37059

4.8MEDIUM

Key Information:

Vendor
CVE Published:
29 August 2022

What is CVE-2022-37059?

The Subrion CMS version 4.2.1 contains a Cross Site Scripting (XSS) vulnerability within its Admin Panel. This flaw enables attackers to inject arbitrary code through the Login Field, posing significant security risks to systems utilizing this content management system. Attackers may exploit this vulnerability to execute malicious scripts that could manipulate user sessions, steal credentials, or conduct further attacks on the system.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.