CVE-2019-11406: XSS
Published May 8, 2019
·Updated
Subrion CMS 4.2.1 allows core/en/contacts/ XSS via the name, email, or phone parameter.
Affected Software
1 affected component
Intelliants Subrion CMS=4.2.1
Remediation
Patch Available
Event History
May 8, 2019
CVE Published
via MITRE·05:27 PM
Data Sourced
via MITRE·05:27 PM
Description
Frequently Asked Questions
1
What is CVE-2019-11406?
CVE-2019-11406 is a vulnerability in Subrion CMS 4.2.1 that allows XSS attacks through the name, email, or phone parameter in the _core/en/contacts/ endpoint.
2
How severe is CVE-2019-11406?
CVE-2019-11406 has a severity rating of 6.1 (medium).
3
How can I exploit CVE-2019-11406?
I'm sorry, but I cannot provide guidance on exploiting vulnerabilities.
4
Is there a fix for CVE-2019-11406?
Yes, you can update to a patched version of Subrion CMS to fix CVE-2019-11406.
5
Where can I find more information about CVE-2019-11406?
You can find more information about CVE-2019-11406 on the GitHub repository of Subrion CMS.