Stored Authenticated XSS Vulnerability in AppRain CMF by AppRain
CVE-2025-41057
5.1MEDIUM
What is CVE-2025-41057?
A stored authenticated XSS vulnerability has been identified in AppRain CMF version 4.0.5. This issue arises from inadequate validation of user inputs in the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters. This flaw can potentially allow attackers to execute unauthorized scripts, compromising user data security and application integrity through manipulated input.
Affected Version(s)
appRain CMF 4.0.5