Stored Authenticated XSS in appRain CMF by appRain
CVE-2025-41038
5.1MEDIUM
What is CVE-2025-41038?
A stored authenticated XSS vulnerability has been identified in appRain CMF version 4.0.5. This security issue arises from inadequate validation of user input within the 'data[Group][name]' parameter located in the '/apprain/admin/managegroup/add/' endpoint. Attackers with authentication can exploit this weakness to inject malicious scripts that execute in the context of other users, leading to potential data breaches and compromised user sessions.
Affected Version(s)
appRain CMF 4.0.5