CVE-2019-11406
Subrion CMS 4.2.1 allows _core/en/contacts/ XSS via the name, email, or phone parameter.
Subrion CMS 4.2.1 allows _core/en/contacts/ XSS via the name, email, or phone parameter.
MEDIUM · CVSS 6.1
EPSS 0.0024
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0