PT-2022-11420 · Unknown · Subrion Cms

Aq-Xiaobai

·

Published

2022-06-11

·

Updated

2022-06-17

·

CVE-2021-41502

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Subrion CMS version 4.2.1
Description The issue is related to a stored cross-site scripting (XSS) vulnerability. This vulnerability can execute malicious JavaScript code by modifying the name of the uploaded image, closing the html tag, or adding the onerror attribute.
Recommendations For Subrion CMS version 4.2.1, as a temporary workaround, consider restricting the upload of images or validating the image names to prevent malicious code execution. Additionally, avoid using the onerror attribute in image tags until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41502
GHSA-JVQ4-CGFW-JGF4

Affected Products

Subrion Cms