PT-2022-11420 · Unknown · Subrion Cms
Aq-Xiaobai
·
Published
2022-06-11
·
Updated
2022-06-17
·
CVE-2021-41502
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Subrion CMS version 4.2.1
Description
The issue is related to a stored cross-site scripting (XSS) vulnerability. This vulnerability can execute malicious JavaScript code by modifying the name of the uploaded image, closing the html tag, or adding the
onerror attribute.Recommendations
For Subrion CMS version 4.2.1, as a temporary workaround, consider restricting the upload of images or validating the image names to prevent malicious code execution. Additionally, avoid using the
onerror attribute in image tags until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Subrion Cms