Lucene search

K
osvGoogleOSV:GHSA-XVGX-668J-F67P
HistoryMay 24, 2022 - 5:17 p.m.

Subrion CMS XSS

2022-05-2417:17:57
Google
osv.dev
2
subrion cms
xss
security
remote attacker
javascript code
output encoding

EPSS

0.001

Percentile

50.0%

An XSS issue was identified on the Subrion CMS 4.2.1 /panel/configuration/general settings page. A remote attacker can inject arbitrary JavaScript code in the v[language_switch] parameter (within multipart/form-data), which is reflected back within a user’s browser without proper output encoding.

EPSS

0.001

Percentile

50.0%