CVE-2019-17225: XSS
Published Oct 6, 2019
·Updated
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue.
Affected Software
1 affected component
Intelliants Subrion=4.2.1
Event History
Oct 6, 2019
CVE Published
via MITRE·04:46 PM
Data Sourced
via MITRE·04:46 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for Subrion 4.2.1?
The vulnerability ID for Subrion 4.2.1 is CVE-2019-17225.
2
What is the severity rating of CVE-2019-17225?
CVE-2019-17225 has a severity rating of medium (5.4).
3
How does Subrion 4.2.1 allow XSS?
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, also known as an "Admin Member JSON Update" issue.
4
How can I check if my Subrion installation is affected by CVE-2019-17225?
You can check if your Subrion installation is affected by CVE-2019-17225 by verifying that your version is 4.2.1.
5
Are there any known fixes for CVE-2019-17225?
Currently, there are no known fixes for CVE-2019-17225. It is recommended to update to the latest version of Subrion when a fix becomes available.