CVE-2021-41502: XSS
An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execute malicious JavaScript code by modifying the name of the uploaded image, closing the html tag, or adding the onerror attribute.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-41502?
The severity of CVE-2021-41502 is medium with a CVSS score of 5.4.
What software is affected by CVE-2021-41502?
Subrion CMS version 4.2.1 is affected by CVE-2021-41502.
What is the vulnerability type of CVE-2021-41502?
CVE-2021-41502 is a stored cross-site scripting (XSS) vulnerability.
How can an attacker exploit CVE-2021-41502?
An attacker can exploit CVE-2021-41502 by modifying the name of the uploaded image, closing the html tag, or adding the onerror attribute to execute malicious JavaScript code.
Is there a fix available for CVE-2021-41502?
As a workaround, ensure that user-uploaded content is properly validated and sanitized. The vendor has released a patch to address this issue, so it is recommended to update to the latest version of Subrion CMS.