ZeroHour

CVE-2021-41502

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p45
Published
()
Modified
Description

An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execute malicious JavaScript code by modifying the name of the uploaded image, closing the html tag, or adding the onerror attribute.

Vendors
intelliants
Products
subrion cms
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.