CVE-2018-14840
MEDIUMSubrion CMS 4.2.1 - XSS
Title source: llmDescription
uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads).
Exploits (1)
Scores
CVSS v3
6.1
EPSS
0.0307
EPSS Percentile
86.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
intelliants/subrion
4.2.1
intelliants/subrion
0 - 4.2.2Packagist
Published
Aug 02, 2018
Tracked Since
Feb 18, 2026