Stored XSS Vulnerability in appRain CMF by appRain
CVE-2025-41054
5.1MEDIUM
What is CVE-2025-41054?
A stored Cross-Site Scripting (XSS) vulnerability exists in appRain CMF version 4.0.5, which is triggered by improper validation of user input in the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters. This lack of sanitization can allow attackers to inject malicious scripts, potentially compromising user sessions and leading to unauthorized actions.
Affected Version(s)
appRain CMF 4.0.5