Subrion CMS is vulnerable to Cross-Site Scripting (XSS)
Moderate severity
GitHub Reviewed
Published
Nov 9, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Description
Published by the National Vulnerability Database
Nov 9, 2022
Published to the GitHub Advisory Database
Nov 9, 2022
Reviewed
Nov 9, 2022
Last updated
Jan 30, 2023
A cross-site scripting (XSS) vulnerability in the /panel/fields/add component of Intelliants Subrion CMS version 4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Field default value text field.
References