High severity8.8NVD Advisory· Published Mar 27, 2017· Updated May 13, 2026
CVE-2017-6002
CVE-2017-6002
Description
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.
Affected products
1- cpe:2.3:a:intelliants:subrion_cms:4.0.5.10:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.yiwang6.cn/Subrion.docxnvdThird Party Advisory
News mentions
0No linked articles in our index yet.