Home

Description

Multiple reflected cross-site scripting (XSS) vulnerabilities in the installation module of Subrion CMS v4.2.1 allows attackers to execute arbitrary Javascript in the context of the user's browser via injecting a crafted payload into the dbuser, dbpwd, and dbname parameters.

PUBLISHED Reserved 2026-01-09 | Published 2026-02-02 | Updated 2026-02-03 | Assigner mitre

References

github.com/...on-CMS-4.2.1/blob/main/subrion-cms-exploit.txt

cve.org (CVE-2025-70958)

nvd.nist.gov (CVE-2025-70958)

Download JSON