PT-2026-49163 · Intelliants · Subrion Cms
CVSS v2.0
3.3
Low
| Vector | AV:N/AC:L/Au:M/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Intelliants Subrion CMS versions prior to 4.0.4
Description
Cross site scripting is possible via the Blocks Endpoint. Remote attackers can exploit this by manipulating the CSS class name argument. Cross site scripting is a type of security flaw that allows attackers to inject malicious scripts into web pages viewed by other users.
Recommendations
Update to a version newer than 4.0.3. As a temporary workaround, restrict access to the Blocks Endpoint to minimize the risk of exploitation.
Exploit
Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Subrion Cms