Lucene search

K
osvGoogleOSV:GHSA-JVQ4-CGFW-JGF4
HistoryJun 12, 2022 - 12:00 a.m.

Cross site scripting in intelliants/subrion

2022-06-1200:00:44
Google
osv.dev
8
cross-site scripting
subrion cms
stored xss
vulnerability
javascript
image upload

EPSS

0.001

Percentile

24.8%

An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execute malicious JavaScript code by modifying the name of the uploaded image, closing the html tag, or adding the onerror attribute.

EPSS

0.001

Percentile

24.8%

Related for OSV:GHSA-JVQ4-CGFW-JGF4