CVE-2019-7356: XSS
Published Nov 4, 2020
·Updated
Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter.
Affected Software
1 affected component
Intelliants Subrion=4.2.1
Remediation
Patch Available
Event History
Nov 4, 2020
CVE Published
via MITRE·07:25 PM
Data Sourced
via MITRE·07:25 PM
Description
Frequently Asked Questions
1
What is CVE-2019-7356?
CVE-2019-7356 is a vulnerability in Subrion CMS v4.2.1 that allows for XSS attacks via the panel/phrases/VALUE parameter.
2
How severe is CVE-2019-7356?
CVE-2019-7356 has a severity rating of 5.4, which is considered medium.
3
How does CVE-2019-7356 affect Subrion CMS?
CVE-2019-7356 affects Subrion CMS v4.2.1 by enabling XSS attacks through the panel/phrases/VALUE parameter.
4
What is the Common Weakness Enumeration (CWE) for CVE-2019-7356?
The CWE for CVE-2019-7356 is CWE-79, which is related to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
5
How can I fix CVE-2019-7356 in Subrion CMS v4.2.1?
To fix CVE-2019-7356 in Subrion CMS v4.2.1, it is recommended to update to the latest version or apply the patches provided by the vendor.