CVE-2025-70958: Subrion CMS vulnerable to cross-site scripting
Multiple reflected Cross-site Scripting (XSS) vulnerabilities in the installation module of Subrion CMS v4.2.1 allow attackers to execute arbitrary Javascript in the context of the user’s browser via injecting a crafted payload into the dbuser, dbpwd, and dbname parameters.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-70958 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →