CVE-2018-16629: XSS
Published Dec 4, 2018
·Updated
panel/uploads/#elfl1XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
Other sources
panel/uploads/#elfl1XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
Affected Software
2 affected components
composer/intelliants/subrion<=4.2.1
Intelliants Subrion CMS=4.2.1
Event History
Dec 4, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
May 14, 2022
Advisory Published
01:31 AM
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-16629.
2
What is the title of this vulnerability?
The title of this vulnerability is 'panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.'
3
What is the affected software for this vulnerability?
The affected software is Subrion CMS v4.2.1.
4
What is the severity of CVE-2018-16629?
The severity of CVE-2018-16629 is medium, with a severity value of 4.8.
5
How can I fix CVE-2018-16629?
To fix CVE-2018-16629, it is recommended to update Subrion CMS to the latest version available.