cve/2025/CVE-2025-41056.md
2025-09-29 21:09:30 +02:00

882 B

CVE-2025-41056

Description

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/hysontable.

POC

Reference

No PoCs from references.

Github