GHSA-jvq4-cgfw-jgf4

Source
https://github.com/advisories/GHSA-jvq4-cgfw-jgf4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-jvq4-cgfw-jgf4/GHSA-jvq4-cgfw-jgf4.json
Aliases
Published
2022-06-12T00:00:44Z
Modified
2023-11-08T04:06:59.468617Z
Details

An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execute malicious JavaScript code by modifying the name of the uploaded image, closing the html tag, or adding the onerror attribute.

References

Affected packages

Packagist / intelliants/subrion

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Last affected
4.2.1

Affected versions

v4.*

v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.1.0
v4.1.1
v4.1.2
v4.1.3
v4.1.4
v4.1.5
v4.2.0
v4.2.1