A vulnerability, which was classified as problematic, was found in appRain CMF 4.0.5. This affects an unknown function of the file /apprain/appreport/manage/. The manipulation of the argument data[AppReportCode][id]/data[AppReportCode][name] results in cross site scripting.

This vulnerability is identified as CVE-2025-41043. The attack can be executed remotely. There is not any exploit available.