Stored Authenticated XSS Vulnerability in appRain CMF 4.0.5
CVE-2025-41040
5.1MEDIUM
What is CVE-2025-41040?
A vulnerability exists in appRain CMF version 4.0.5 that allows attackers to exploit stored authenticated cross-site scripting (XSS) due to inadequate validation of user input from specific parameters. This flaw can lead to unauthorized access and manipulation of user data, posing serious security risks for web applications utilizing this platform. Attackers can inject malicious scripts through the 'data[code]', 'data[lang][0][key]', 'data[lang][0][value]', 'data[lang][1][key]', and 'data[title]' inputs, compromising the integrity of the affected application.
Affected Version(s)
appRain CMF 4.0.5