LiveActive security incident?Get immediate response
CVE Record

CVE-2020-22330: Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page.

Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

Subrion 4.2.1 has a reported cross-site scripting issue in the page title field when adding a page. If reachable by a malicious or compromised user with page-creation access, injected script could run in another user's browser. The public record does not provide CVSS, confirmed exploitation, or vendor remediation details.

Executive priority

Treat this as a targeted remediation item for known Subrion 4.2.1 sites, not a broad emergency. Prioritize if the CMS is internet-facing or allows non-admin page creation.

Technical view

CVE-2020-22330 describes XSS in Subrion 4.2.1 through the title value during page creation. The bundle does not specify whether this is stored or reflected, required privileges, affected interfaces, browser impact, or fixed versions. KEV status is false, and no source here reports active exploitation.

Likely exposure

Exposure is most likely limited to organizations running Subrion 4.2.1, especially installations where untrusted, lower-privileged, or compromised accounts can create CMS pages.

Exploitation context

The provided sources only describe the vulnerable input location. They do not confirm public exploitation, KEV listing, exploit reliability, privilege requirements, or whether anonymous users can reach the affected workflow.

Researcher notes

Evidence is sparse: no CVSS, CWE, CPE, patch reference, or detailed exploitability notes are included. Validate impact in a controlled environment and avoid assuming affected versions beyond Subrion 4.2.1.

Mitigation direction

  • Identify any Subrion 4.2.1 deployments.
  • Check Subrion or maintainer guidance for fixed versions or patches.
  • Restrict page-creation permissions to trusted administrators.
  • Review CMS roles for stale, shared, or compromised accounts.
  • Add compensating content sanitization controls where supported.

Validation and detection

  • Inventory internet-facing and internal Subrion instances.
  • Confirm deployed Subrion versions against 4.2.1.
  • Review who can add pages in each CMS instance.
  • Check whether page titles are encoded before rendering.
  • Review logs for unusual page title changes.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2020-22330 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.