CVE-2024-25399: XSS
Published Feb 27, 2024
·Updated
Subrion CMS 4.2.1 is vulnerable to Cross Site Scripting (XSS) via adminer.php.
Affected Software
2 affected components
Intelliants Subrion CMS=4.2.1
composer/intelliants/subrion<=4.2.1
Event History
Feb 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-25399?
CVE-2024-25399 has a medium severity rating due to its potential impact on user data through Cross Site Scripting (XSS).
2
How do I fix CVE-2024-25399?
To fix CVE-2024-25399, upgrade Subrion CMS to a version higher than 4.2.1 that contains the necessary security patches.
3
What type of vulnerability is CVE-2024-25399?
CVE-2024-25399 is classified as a Cross Site Scripting (XSS) vulnerability affecting version 4.2.1 of Subrion CMS.
4
Who is affected by CVE-2024-25399?
Users of Subrion CMS version 4.2.1 are affected by CVE-2024-25399 and should take immediate action to mitigate the risk.
5
Can CVE-2024-25399 lead to data breaches?
Yes, CVE-2024-25399 can potentially lead to data breaches through malicious scripts executing in the context of a user's session.