VYPR
Moderate severityNVD Advisory· Published Sep 27, 2023· Updated Sep 24, 2024

CVE-2023-43830

CVE-2023-43830

Description

A Cross-site scripting (XSS) vulnerability in /panel/configuration/financial/ of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into several fields: 'Minimum deposit', 'Maximum deposit' and/or 'Maximum balance'.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Subrion CMS 4.2.1 financial configuration fields vulnerable to stored XSS, allowing arbitrary web script execution.

Vulnerability

Overview Subrion CMS version 4.2.1 contains a stored cross-site scripting (XSS) vulnerability in the financial configuration panel at /panel/configuration/financial/. The fields 'Minimum deposit', 'Maximum deposit', and 'Maximum balance' lack proper input sanitization, allowing an attacker to inject arbitrary web scripts or HTML [1][3].

Exploitation

An attacker with administrative access can inject a crafted payload into one of the vulnerable fields. When a user, including other administrators, visits the /profile/funds/ page, the stored payload executes in the context of the victim's browser [3]. No additional authentication is required for the victim beyond being logged into the CMS.

Impact

Successful exploitation enables the attacker to execute arbitrary JavaScript in the browser of any user viewing the funds page. This can lead to session hijacking, defacement, or exfiltration of sensitive data. The attack does not require direct interaction with the victim beyond the normal use of the application.

Mitigation

As of the CVE publication date (2023-09-27), no official patch has been released. Users are advised to restrict access to the financial configuration panel, manually sanitize the affected fields, or upgrade to a newer version if available [1][3].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
intelliants/subrionPackagist
<= 4.2.1

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.