Stored Authenticated XSS Vulnerability in appRain CMF by appRain
CVE-2025-41060
5.1MEDIUM
What is CVE-2025-41060?
A security flaw was identified in appRain CMF version 4.0.5, which allows for stored authenticated cross-site scripting (XSS) attacks. This vulnerability arises due to insufficient validation of user input within specific parameters, namely 'data[Addon][layouts]' and 'data[Addon][layouts_except]'. Attackers can exploit this weakness to inject malicious scripts, potentially compromising user accounts and data integrity.
Affected Version(s)
appRain CMF 4.0.5