CVE-2018-14840: Intelliants Subrion
Medium severity, CVSS 6.1. EPSS: 3.7% chance of exploitation in the next 30 days.
uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads).
Affected products
- Intelliants Subrion: version 4.2.1 only
Published 2018-08-02. Last modified 2026-06-17.