Moderate severityNVD Advisory· Published Dec 10, 2014· Updated May 6, 2026
CVE-2014-9120
CVE-2014-9120
Description
Cross-site scripting (XSS) vulnerability in Subrion CMS before 3.2.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to subrion/search/.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
intelliants/subrionPackagist | < 3.2.3 | 3.2.3 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- dev.subrion.org/versions/130nvdBroken LinkVendor AdvisoryWEB
- github.com/advisories/GHSA-xjr9-2wf2-3v4wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2014-9120ghsaADVISORY
- www.netsparker.com/xss-vulnerability-in-subrion-cms/nvdThird Party Advisory
- www.netsparker.com/xss-vulnerability-in-subrion-cmsghsaWEB
News mentions
0No linked articles in our index yet.