Stored Authenticated XSS in AppRain CMF File Manager
CVE-2025-41037
5.1MEDIUM
What is CVE-2025-41037?
A stored authenticated XSS vulnerability has been identified in AppRain CMF version 4.0.5. This issue arises from inadequate validation of user input, specifically through the 'data[FileManager][search]' parameter in the /apprain/admin/filemanager module. Attackers can exploit this vulnerability to inject malicious scripts, potentially compromising user accounts and the integrity of the application.
Affected Version(s)
appRain CMF 4.0.5