Vulnerability Description
Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intelliants | Subrion Cms | 4.2.1 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/160783/Subrion-CMS-4.2.1-Cross-Site-ScriptiExploitThird Party AdvisoryVDB Entry
- https://github.com/intelliants/subrion/issues/880ExploitThird Party Advisory
- http://packetstormsecurity.com/files/160783/Subrion-CMS-4.2.1-Cross-Site-ScriptiExploitThird Party AdvisoryVDB Entry
- https://github.com/intelliants/subrion/issues/880ExploitThird Party Advisory
FAQ
What is CVE-2020-35437?
CVE-2020-35437 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI.
How severe is CVE-2020-35437?
CVE-2020-35437 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-35437?
Check the references section above for vendor advisories and patch information. Affected products include: Intelliants Subrion Cms.