Stored XSS Vulnerability in appRain CMF Affects User Input Validation
CVE-2025-41039
5.1MEDIUM
What is CVE-2025-41039?
A stored authenticated cross-site scripting (XSS) vulnerability has been identified in appRain CMF version 4.0.5, triggered by inadequate validation of user-supplied data. This issue arises through various parameters, including 'data[sconfig][admin_landing_page]' and others in the configuration options of the admin panel. If exploited, this vulnerability allows an attacker to inject malicious scripts that can execute within the context of the affected application, potentially compromising user sessions and sensitive information. Proper input validation mechanisms are crucial to prevent such vulnerabilities.
Affected Version(s)
appRain CMF 4.0.5