CVE-2025-70958 | Subrion CMS 4.2.1 Installation dbuser/dbpwd/dbname cross site scripting
A vulnerability, which was classified as problematic, has been found in Subrion CMS 4.2.1. This issue affects some unknown processing of the component Installation Module. This manipulation of the argument dbuser/dbpwd/dbname causes cross site scripting.
This vulnerability is tracked as CVE-2025-70958. The attack is possible to be carried out remotely. Moreover, an exploit is present.