CVE-2018-16629
panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
MEDIUM · CVSS 4.8
EPSS 0.00321
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0