# Exploit Title: Subrion CMS 4.2.1 - Stored Cross-Site Scripting (XSS) # Date: 2022-08-10 # Exploit Author: Sinem Şahin # Vendor Homepage: https://intelliants.com/ # Version: 4.2.1 # Tested on: Windows & XAMPP ==> Tutorial <== 1- Go to the following url. => http://(HOST)/panel/fields/add 2- Write XSS Payload into the tooltip value of the field add page. 3- Press "Save" button. 4- Go to the following url. => http://(HOST)/panel/members/add XSS Payload ==> " Reference: ://github.com/intelliants/subrion/issues/895