Stored Authenticated XSS in appRain CMF by appRain
CVE-2025-41056
5.1MEDIUM
What is CVE-2025-41056?
A stored authenticated cross-site scripting vulnerability exists in appRain CMF version 4.0.5, caused by improper validation of user inputs through specific parameters including 'data[Addon][layouts]' and 'data[Addon][layouts_except]'. This security flaw could allow an attacker to execute arbitrary scripts in the context of the user’s session, posing a risk to users and the integrity of the application.
Affected Version(s)
appRain CMF 4.0.5