CVE-2021-41502

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-41502
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41502.json
Aliases
Published
2022-06-11T14:15:11Z
Modified
2023-11-29T09:04:14.652765Z
Details

An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execute malicious JavaScript code by modifying the name of the uploaded image, closing the html tag, or adding the onerror attribute.

References

Affected packages

Git / github.com/intelliants/subrion

Affected ranges

Type
GIT
Repo
https://github.com/intelliants/subrion
Events
Introduced
0The exact introduced commit is unknown
Last affected

Affected versions

v4.*

v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.1.0
v4.1.1
v4.1.2
v4.1.3
v4.1.4
v4.1.5
v4.2.0
v4.2.1