Stored XSS Vulnerability in appRain CMF Affects Multiple Versions
CVE-2025-41046
5.1MEDIUM
What is CVE-2025-41046?
A critical security flaw has been identified in appRain CMF version 4.0.5 that allows for stored authenticated cross-site scripting (XSS). The vulnerability arises from inadequate validation of user input, particularly through parameters such as 'data[Addon][layouts]' and 'data[Addon][layouts_except]' during addon updates. This flaw could allow attackers to inject malicious scripts, potentially compromising user data and leading to unauthorized actions within the application.
Affected Version(s)
appRain CMF 4.0.5