CVE-2018-16631: XSS
Published Dec 4, 2018
·Updated
Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter.
Affected Software
1 affected component
Intelliants Subrion CMS=4.2.1
Event History
Dec 4, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-16631?
CVE-2018-16631 is a vulnerability in Subrion CMS v4.2.1 that allows cross-site scripting (XSS) attacks through the panel/configuration/general/SITE TITLE parameter.
2
How severe is CVE-2018-16631?
CVE-2018-16631 has a severity rating of medium with a CVSS score of 5.4.
3
How does CVE-2018-16631 affect Subrion CMS?
CVE-2018-16631 affects Subrion CMS version 4.2.1.
4
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2018-16631?
CVE-2018-16631 is associated with CWE-79, which is the Cross-Site Scripting (XSS) vulnerability.
5
How can I mitigate the CVE-2018-16631 vulnerability?
To mitigate the CVE-2018-16631 vulnerability, update Subrion CMS to a version that addresses the XSS issue.