Stored Authenticated XSS Vulnerability in appRain CMF by appRain
CVE-2025-41052
5.1MEDIUM
What is CVE-2025-41052?
A security vulnerability has been identified in appRain CMF version 4.0.5 that allows for stored authenticated cross-site scripting (XSS) through insufficient validation of user input. This vulnerability is triggered via the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters within the /apprain/developer/addons/update/canvasjs endpoint, potentially enabling attackers to inject malicious scripts that could lead to unauthorized data access and manipulation.
Affected Version(s)
appRain CMF 4.0.5