CVE-2025-70958: XSS
Multiple reflected Cross-site Scripting (XSS) vulnerabilities in the installation module of Subrion CMS v4.2.1 allow attackers to execute arbitrary Javascript in the context of the user's browser via injecting a crafted payload into the dbuser, dbpwd, and dbname parameters.
Other sources
Multiple reflected cross-site scripting (XSS) vulnerabilities in the installation module of Subrion CMS v4.2.1 allows attackers to execute arbitrary Javascript in the context of the user's browser via injecting a crafted payload into the dbuser, dbpwd, and dbname parameters.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-70958?
CVE-2025-70958 is classified as a moderate severity vulnerability due to the potential for reflected cross-site scripting attacks.
How do I fix CVE-2025-70958?
To fix CVE-2025-70958, upgrade Subrion CMS to a version later than 4.2.1 where the vulnerabilities are addressed.
What impact does CVE-2025-70958 have on users?
CVE-2025-70958 can allow attackers to execute arbitrary JavaScript in the context of users' browsers, leading to session hijacking or data theft.
Which software versions are affected by CVE-2025-70958?
CVE-2025-70958 affects Subrion CMS version 4.2.1 and prior versions.
Can CVE-2025-70958 be exploited by unauthenticated attackers?
Yes, CVE-2025-70958 can be exploited by unauthenticated attackers since it involves reflected cross-site scripting.