An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execute malicious JavaScript code by modifying the name of the uploaded image, closing the html tag, or adding the onerror attribute.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-06-11T13:55:45

Updated: 2024-08-04T03:15:28.392Z

Reserved: 2021-09-20T00:00:00

Link: CVE-2021-41502

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-06-11T14:15:11.090

Modified: 2022-06-17T17:31:33.673

Link: CVE-2021-41502

cve-icon Redhat

No data.