An issue exists in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execute malicious JavaScript code by modifying the name of the uploaded image, closing the html tag, or adding the onerror attribute.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
intelliants subrion cms 4.2.1 |