Stored Authenticated XSS Vulnerability in appRain CMF by appRain
CVE-2025-41058
5.1MEDIUM
What is CVE-2025-41058?
A stored authenticated XSS vulnerability exists in appRain CMF version 4.0.5. This issue arises from insufficient validation of user inputs in the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters located in /apprain/developer/addons/update/row_manager. As a result, malicious scripts can be injected and executed in the context of the affected application, potentially allowing an attacker to take control of user sessions or manipulate web sessions to conduct further attacks.
Affected Version(s)
appRain CMF 4.0.5