Vulnerabilities > Intelliants > Subrion CMS > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-06-11 | CVE-2021-41502 | Cross-site Scripting vulnerability in Intelliants Subrion CMS 4.2.1 An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execute malicious JavaScript code by modifying the name of the uploaded image, closing the html tag, or adding the onerror attribute. | 3.5 |
2022-02-24 | CVE-2021-43724 | Cross-site Scripting vulnerability in Intelliants Subrion CMS A Cross Site Scripting (XSS) vulnerability exits in Subrion CMS through 4.2.1 in the Create Page functionality of the admin Account via a SGV file. | 3.5 |
2021-08-05 | CVE-2020-22392 | Cross-site Scripting vulnerability in Intelliants Subrion CMS 4.2.2 Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file. | 3.5 |
2018-12-04 | CVE-2018-16629 | Cross-site Scripting vulnerability in Intelliants Subrion CMS 4.2.1 panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element. | 3.5 |
2018-12-04 | CVE-2018-16631 | Cross-site Scripting vulnerability in Intelliants Subrion CMS 4.2.1 Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter. | 3.5 |