Stored Authenticated XSS Vulnerability in appRain CMF 4.0.5
CVE-2025-41040
What is CVE-2025-41040?
A vulnerability exists in appRain CMF version 4.0.5 that allows attackers to exploit stored authenticated cross-site scripting (XSS) due to inadequate validation of user input from specific parameters. This flaw can lead to unauthorized access and manipulation of user data, posing serious security risks for web applications utilizing this platform. Attackers can inject malicious scripts through the 'data[code]', 'data[lang][0][key]', 'data[lang][0][value]', 'data[lang][1][key]', and 'data[title]' inputs, compromising the integrity of the affected application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
appRain CMF 4.0.5
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
