PT-2022-11515 · Unknown+1 · Subrion Cms+1

Onemanteam123321

·

Published

2022-04-29

·

Updated

2022-05-10

·

CVE-2021-41948

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Subrion CMS version 4.2.1 and earlier
Description A cross-site scripting (XSS) issue exists in the contact us plugin via the List of subjects. This can be exploited by someone with administrative privileges when they log in to the admin panel.
Recommendations For Subrion CMS version 4.2.1 and earlier, consider disabling the contact us plugin until a patch is available. Restrict access to the admin panel to minimize the risk of exploitation. Avoid using the List of subjects feature in the contact us plugin until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41948
GHSA-JV64-2M3X-6V4Q

Affected Products

Subrion Cms
Contacts