Multiple reflected cross-site scripting (XSS) vulnerabilities in the installation module of Subrion CMS v4.2.1 allows attackers to execute arbitrary Javascript in the context of the user's browser via injecting a crafted payload into the dbuser, dbpwd, and dbname parameters.
History

Mon, 02 Feb 2026 23:15:00 +0000

Type Values Removed Values Added
Description Multiple reflected cross-site scripting (XSS) vulnerabilities in the installation module of Subrion CMS v4.2.1 allows attackers to execute arbitrary Javascript in the context of the user's browser via injecting a crafted payload into the dbuser, dbpwd, and dbname parameters.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-02-02T19:49:55.440Z

Reserved: 2026-01-09T00:00:00.000Z

Link: CVE-2025-70958

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-02T23:16:02.697

Modified: 2026-02-02T23:16:02.697

Link: CVE-2025-70958

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.