4.8
CVSSv3

CVE-2022-37059

Published: 29/08/2022 Updated: 01/09/2022
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 0

Vulnerability Summary

Cross Site Scripting (XSS) in Admin Panel of Subrion CMS 4.2.1 allows malicious user to inject arbitrary code via Login Field

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

intelliants subrion cms 4.2.1

Github Repositories

Repository for Mine Security Research

Exploit Title: Cross Site Scripting (XSS) in Admin Panel of Subrion CMS 421 Date: 24 July 2022 Exploit Author: RashidKhan Pathan Vendor Homepage: subrionorg/ Software Link: subrionorg/download/ Version: v421 Tested on: Windows 10, Kali Linux CVE : CVE-2022-37059 Steps to Reproduce: 1: Goto on This URL localhost/subrioncms/panel/ 2: Copy the Payload