Lucene search

K
osvGoogleOSV:GHSA-XJR9-2WF2-3V4W
HistoryMay 14, 2022 - 2:00 a.m.

Subrion CMS Cross-site scripting in search

2022-05-1402:00:54
Google
osv.dev
5
subrion cms
cross-site scripting
vulnerability

EPSS

0.001

Percentile

43.3%

A cross-site scripting (XSS) vulnerability in Subrion CMS before 3.2.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to subrion/search/.

EPSS

0.001

Percentile

43.3%

Related for OSV:GHSA-XJR9-2WF2-3V4W