PT-2026-5704 · Unknown · Subrion Cms

CVE-2025-70958

·

Published

2026-02-02

·

Updated

2026-02-11

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Subrion CMS version 4.2.1
Description The installation module of Subrion CMS contains reflected cross-site scripting (XSS) flaws. These flaws allow attackers to execute arbitrary Javascript in the context of a user's browser. Exploitation occurs by injecting a crafted payload into the dbuser, dbpwd, and dbname parameters.
Recommendations Apply a fix or update to a newer version of Subrion CMS. As a temporary workaround, sanitize the dbuser, dbpwd, and dbname parameters during the installation process to prevent the injection of malicious scripts.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-70958
GHSA-9JJM-MC56-3QXV

Affected Products

Subrion Cms