CVE-2021-41948: XSS
Published Apr 29, 2022
·Updated
A cross-site scripting (XSS) vulnerability exists in the "contact us" plugin for Subrion CMS <= 4.2.1 version via "List of subjects".
Affected Software
1 affected component
Intelliants Subrion<=4.2.1
Event History
Apr 29, 2022
CVE Published
via MITRE·01:41 PM
Data Sourced
via MITRE·01:41 PM
Description
Frequently Asked Questions
1
What is CVE-2021-41948?
CVE-2021-41948 is a cross-site scripting (XSS) vulnerability that exists in the contact us plugin for Subrion CMS version 4.2.1 and below.
2
How severe is CVE-2021-41948?
CVE-2021-41948 has a severity level of medium (5.4).
3
How does CVE-2021-41948 impact Subrion CMS?
CVE-2021-41948 allows attackers to inject malicious code into web pages viewed by users of the Subrion CMS contact us plugin.
4
What is the affected version of Subrion CMS for CVE-2021-41948?
CVE-2021-41948 affects Subrion CMS versions up to and including 4.2.1.
5
Is there a fix available for CVE-2021-41948?
Yes, upgrading to a version of Subrion CMS that is higher than 4.2.1 will fix CVE-2021-41948.