Stored Authenticated XSS Vulnerability in appRain CMF from appRain
CVE-2025-41044
5.1MEDIUM
What is CVE-2025-41044?
A stored authenticated XSS vulnerability exists in appRain CMF version 4.0.5 due to insufficient validation of user input within the 'data[Page][name]' parameter, specifically in the /apprain/page/manage-static-pages/create endpoint. This flaw could allow attackers to inject malicious scripts, potentially compromising user sessions and system integrity.
Affected Version(s)
appRain CMF 4.0.5