CVE-2018-14840: XSS
Published Aug 2, 2018
·Updated
uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads).
Other sources
uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads).
Affected Software
2 affected componentsFixes available
composer/intelliants/subrion<4.2.2
4.2.2
Intelliants Subrion=4.2.1
Remediation
Event History
Aug 2, 2018
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
May 14, 2022
Advisory Published
02:00 AM
Frequently Asked Questions
1
What is CVE-2018-14840?
CVE-2018-14840 is a vulnerability in Subrion CMS 4.2.1 that allows XSS due to the lack of blocking .html file uploads.
2
How severe is CVE-2018-14840?
CVE-2018-14840 has a severity rating of 6.1 (Medium).
3
How does CVE-2018-14840 affect Subrion CMS?
CVE-2018-14840 affects Subrion CMS versions 4.2.1 and prior.
4
How can I fix CVE-2018-14840 in Subrion CMS?
To fix CVE-2018-14840 in Subrion CMS, you need to update to version 4.2.2 or later.
5
What is the CWE ID associated with CVE-2018-14840?
CVE-2018-14840 is associated with CWE ID 79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))