Stored XSS Vulnerability in appRain CMF Affects User Input Validation
CVE-2025-41039

5.1MEDIUM

Key Information:

Vendor

Apprain

Vendor
CVE Published:
4 September 2025

What is CVE-2025-41039?

A stored authenticated cross-site scripting (XSS) vulnerability has been identified in appRain CMF version 4.0.5, triggered by inadequate validation of user-supplied data. This issue arises through various parameters, including 'data[sconfig][admin_landing_page]' and others in the configuration options of the admin panel. If exploited, this vulnerability allows an attacker to inject malicious scripts that can execute within the context of the affected application, potentially compromising user sessions and sensitive information. Proper input validation mechanisms are crucial to prevent such vulnerabilities.

Affected Version(s)

appRain CMF 4.0.5

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafael Pedrero
.
CVE-2025-41039 : Stored XSS Vulnerability in appRain CMF Affects User Input Validation