CVE-2018-14835: XSS
Published Aug 2, 2018
·Updated
Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas.
Affected Software
2 affected components
composer/intelliants/subrion<=4.2.1
Subrion Subrion CMS=4.2.1
Remediation
Patch Available
Event History
Aug 2, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
May 14, 2022
Advisory Published
02:57 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-14835?
The severity of CVE-2018-14835 is classified as medium due to its potential for stored XSS attacks.
2
How do I fix CVE-2018-14835?
To fix CVE-2018-14835, update Subrion CMS to version 4.2.2 or higher where the vulnerability is addressed.
3
What type of vulnerability is CVE-2018-14835?
CVE-2018-14835 is a stored cross-site scripting (XSS) vulnerability.
4
Which software versions are affected by CVE-2018-14835?
CVE-2018-14835 affects Subrion CMS version 4.2.1.
5
What impact does CVE-2018-14835 have on web applications?
CVE-2018-14835 can allow attackers to inject malicious scripts into the web application, compromising user data.