-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from unescaped output of user-controlled tooltip content in template files. The GitHub commit adds |escape modifiers to both affected template variables, confirming these were the vulnerable points. The templates handle field rendering in both admin and frontend interfaces, making them the entry points for stored XSS payloads through tooltip fields.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| intelliants/subrion | composer | <= 4.2.1 |
KEV Misses 88% of Exploited CVEs- Get the report