CVE-2025-70958: 
PHP vulnerability analysis and mitigation

Overview

CVE-2025-70958 describes multiple reflected cross-site scripting (XSS) vulnerabilities in the installation module of Subrion CMS v4.2.1, affecting the dbuser, dbpwd, and dbname parameters. The vulnerability allows unauthenticated attackers to inject crafted payloads that execute arbitrary JavaScript in the context of a victim's browser during the CMS installation process. It was published on February 2, 2026, with a GitHub Advisory (GHSA-9jjm-mc56-3qxv) added on February 3, 2026. The CVSS v3.1 base score is 6.1 (Medium) (Github Advisory, RedHat CVE).

Technical details

The root cause is improper neutralization of user-supplied input before it is reflected back in the HTTP response (CWE-79). The installation configuration endpoint (/install/install/configuration/) accepts POST parameters — dbuser, dbpwd, and dbname — and returns their values in the HTML response without HTML encoding or sanitization, allowing characters such as < and > to pass through unescaped. An attacker can craft a POST request containing an SVG-based XSS payload (e.g., '"><svg/onload=alert('xss')>) in any of the affected fields, which the server reflects directly into the page, triggering JavaScript execution in the victim's browser. A public proof-of-concept exploit demonstrating this technique is available on GitHub (Github Advisory, PoC Exploit).

Impact

Successful exploitation enables arbitrary JavaScript execution in the browser of any user accessing the Subrion CMS installation page, which could allow an attacker to steal session cookies, capture database credentials (such as the database username, password, and name entered during setup), or perform unauthorized actions on behalf of the user. Because the vulnerability resides in the installation module and requires no authentication, any administrator or user performing a fresh installation of Subrion CMS v4.2.1 is at risk if the installation endpoint is accessible. The impact is limited to confidentiality and integrity (no availability impact), but exposure of database credentials during installation could facilitate further compromise of the underlying infrastructure (Github Advisory, PoC Exploit).

Exploitability

A public proof-of-concept exploit is available on GitHub, published by researcher Emirhan Yücel, demonstrating the reflected XSS via crafted POST requests to the installation endpoint (PoC Exploit). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.006% (6th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible Subrion CMS v4.2.1 installation endpoints (e.g., /install/install/configuration/) using web search engines or directory scanning tools such as gobuster or ffuf.
  2. Confirm vulnerability: Access the installation configuration page in a browser to verify the form fields dbuser, dbpwd, and dbname are present and the endpoint is reachable.
  3. Craft malicious payload: Prepare an XSS payload such as '"><svg/onload=alert('xss')> to be injected into the affected parameters.
  4. Deliver the payload: Send a crafted HTTP POST request to the installation endpoint with the payload URL-encoded in the dbuser, dbpwd, or dbname parameters (e.g., dbuser=%27%22%3E%3Csvg%2Fonload%3Dalert%28%27xss%27%29%3E). This can be done via a browser, Burp Suite, or curl.
  5. Trigger execution: Convince a target user (e.g., an administrator performing installation) to submit the manipulated form or visit a crafted URL that auto-submits the form. The server reflects the unsanitized input back in the response, executing the JavaScript payload in the victim's browser.
  6. Achieve objective: Use the executed JavaScript to exfiltrate session cookies, capture database credentials entered during installation, or perform actions on behalf of the victim (PoC Exploit).

Indicators of compromise

  • Network: Unusual HTTP POST requests to /install/install/configuration/ containing URL-encoded XSS payloads (e.g., %3Csvg, onload%3D, alert) in the dbuser, dbpwd, or dbname parameters; requests to the installation endpoint from unexpected or external IP addresses.
  • Logs: Web server access logs showing POST requests to the installation path with anomalous parameter values containing HTML/JavaScript special characters (<, >, ", ', svg, onload); repeated access to the installation endpoint after initial setup is complete.
  • File System: Presence of the installation directory (/install/) remaining accessible after CMS setup is complete, indicating the installation module was not removed or restricted post-installation.

Mitigation and workarounds

The GitHub Advisory (GHSA-9jjm-mc56-3qxv) notes that no patched version of Subrion CMS has been released as of the advisory date, and all versions up to and including 4.2.1 are affected. As an immediate workaround, administrators should restrict or disable access to the installation module (/install/) once the CMS setup is complete, ideally by removing the installation directory or blocking access via web server configuration (e.g., .htaccess or firewall rules). Input validation and output encoding should be implemented for all installation parameters. Organizations should monitor for any signs of exploitation during the installation process and conduct security reviews of instances that were installed while the endpoint was publicly accessible (Github Advisory, RedHat CVE).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management