
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-70958 describes multiple reflected cross-site scripting (XSS) vulnerabilities in the installation module of Subrion CMS v4.2.1, affecting the dbuser, dbpwd, and dbname parameters. The vulnerability allows unauthenticated attackers to inject crafted payloads that execute arbitrary JavaScript in the context of a victim's browser during the CMS installation process. It was published on February 2, 2026, with a GitHub Advisory (GHSA-9jjm-mc56-3qxv) added on February 3, 2026. The CVSS v3.1 base score is 6.1 (Medium) (Github Advisory, RedHat CVE).
The root cause is improper neutralization of user-supplied input before it is reflected back in the HTTP response (CWE-79). The installation configuration endpoint (/install/install/configuration/) accepts POST parameters — dbuser, dbpwd, and dbname — and returns their values in the HTML response without HTML encoding or sanitization, allowing characters such as < and > to pass through unescaped. An attacker can craft a POST request containing an SVG-based XSS payload (e.g., '"><svg/onload=alert('xss')>) in any of the affected fields, which the server reflects directly into the page, triggering JavaScript execution in the victim's browser. A public proof-of-concept exploit demonstrating this technique is available on GitHub (Github Advisory, PoC Exploit).
Successful exploitation enables arbitrary JavaScript execution in the browser of any user accessing the Subrion CMS installation page, which could allow an attacker to steal session cookies, capture database credentials (such as the database username, password, and name entered during setup), or perform unauthorized actions on behalf of the user. Because the vulnerability resides in the installation module and requires no authentication, any administrator or user performing a fresh installation of Subrion CMS v4.2.1 is at risk if the installation endpoint is accessible. The impact is limited to confidentiality and integrity (no availability impact), but exposure of database credentials during installation could facilitate further compromise of the underlying infrastructure (Github Advisory, PoC Exploit).
A public proof-of-concept exploit is available on GitHub, published by researcher Emirhan Yücel, demonstrating the reflected XSS via crafted POST requests to the installation endpoint (PoC Exploit). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.006% (6th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory).
/install/install/configuration/) using web search engines or directory scanning tools such as gobuster or ffuf.dbuser, dbpwd, and dbname are present and the endpoint is reachable.'"><svg/onload=alert('xss')> to be injected into the affected parameters.dbuser, dbpwd, or dbname parameters (e.g., dbuser=%27%22%3E%3Csvg%2Fonload%3Dalert%28%27xss%27%29%3E). This can be done via a browser, Burp Suite, or curl./install/install/configuration/ containing URL-encoded XSS payloads (e.g., %3Csvg, onload%3D, alert) in the dbuser, dbpwd, or dbname parameters; requests to the installation endpoint from unexpected or external IP addresses.<, >, ", ', svg, onload); repeated access to the installation endpoint after initial setup is complete./install/) remaining accessible after CMS setup is complete, indicating the installation module was not removed or restricted post-installation.The GitHub Advisory (GHSA-9jjm-mc56-3qxv) notes that no patched version of Subrion CMS has been released as of the advisory date, and all versions up to and including 4.2.1 are affected. As an immediate workaround, administrators should restrict or disable access to the installation module (/install/) once the CMS setup is complete, ideally by removing the installation directory or blocking access via web server configuration (e.g., .htaccess or firewall rules). Input validation and output encoding should be implemented for all installation parameters. Organizations should monitor for any signs of exploitation during the installation process and conduct security reviews of instances that were installed while the endpoint was publicly accessible (Github Advisory, RedHat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."