CVE-2020-35437: XSS
Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /core/profile/ URI.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for Subrion CMS 4.2.1?
The vulnerability ID for Subrion CMS 4.2.1 is CVE-2020-35437.
What is the severity of CVE-2020-35437?
The severity of CVE-2020-35437 is medium, with a CVSS score of 6.1.
How does CVE-2020-35437 affect Subrion CMS 4.2.1?
CVE-2020-35437 affects Subrion CMS 4.2.1 through a Cross-Site Scripting (XSS) vulnerability in the avatar[path] parameter in a POST request to the /_core/profile/ URI.
How can I fix CVE-2020-35437 in Subrion CMS 4.2.1?
To fix CVE-2020-35437 in Subrion CMS 4.2.1, it is recommended to apply the latest security patch or update provided by Intelliants, the developer of Subrion CMS.
Is there any additional information available about CVE-2020-35437?
Yes, you can find additional information about CVE-2020-35437 in the following references: [Packetstorm Security](http://packetstormsecurity.com/files/160783/Subrion-CMS-4.2.1-Cross-Site-Scripting.html) and [GitHub Issue](https://github.com/intelliants/subrion/issues/880).