uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads).
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5361 | uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads). |
Github GHSA |
GHSA-vhqr-3gr2-7px9 | Subrion CMS Cross-site Scripting |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T09:38:13.939Z
Reserved: 2018-08-01T00:00:00.000Z
Link: CVE-2018-14840
No data.
Status : Modified
Published: 2018-08-02T01:29:03.107
Modified: 2024-11-21T03:49:54.433
Link: CVE-2018-14840
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA