{"id":"GHSA-2cmg-vxvh-8h7h","summary":"Subrion CMS XSS","details":"Subrion CMS before 4.1.4 has XSS.","aliases":["CVE-2018-11317"],"modified":"2024-02-16T08:23:57.739826Z","published":"2022-05-24T16:49:19Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-07-20T17:47:18Z","nvd_published_at":"2019-07-03T16:15:00Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-11317"},{"type":"PACKAGE","url":"https://github.com/intelliants/subrion"},{"type":"WEB","url":"https://github.com/intelliants/subrion/blob/610b21d3ff185bd287d55fe016d4266abf04a3bf/includes/classes/ia.admin.sitemap.php#L79-L83"},{"type":"WEB","url":"https://github.com/intelliants/subrion/releases/tag/v4.1.4"}],"affected":[{"package":{"name":"intelliants/subrion","ecosystem":"Packagist","purl":"pkg:composer/intelliants/subrion"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.4"}]}],"versions":["v4.0.0","v4.0.1","v4.0.2","v4.0.3","v4.0.4","v4.0.5","v4.1.0","v4.1.1","v4.1.2","v4.1.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-2cmg-vxvh-8h7h/GHSA-2cmg-vxvh-8h7h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}