VYPR

Subrion CMS

by Intelliants

Source repositories

CVEs (65)

  • CVE-2017-11444CriJul 19, 2017
    risk 0.65cvss 9.8epss 0.13

    Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.

  • CVE-2024-25400CriFeb 27, 2024
    risk 0.64cvss 9.8epss 0.01

    Subrion CMS 4.2.1 is vulnerable to SQL Injection via ia.core.mysqli.php. NOTE: this is disputed by multiple third parties because it refers to an HTTP request to a PHP file that only contains a class, without any mechanism for accepting external input, and the reportedly…

  • CVE-2017-11445CriJul 19, 2017
    risk 0.64cvss 9.8epss 0.01

    Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.

  • CVE-2017-6013CriMar 27, 2017
    risk 0.64cvss 9.8epss 0.02

    Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.

  • CVE-2023-46947HigNov 3, 2023
    risk 0.57cvss 8.8epss 0.01

    Subrion 4.2.1 has a remote command execution vulnerability in the backend.

  • CVE-2021-43464HigApr 4, 2022
    risk 0.57cvss 8.8epss 0.01

    A Remiote Code Execution (RCE) vulnerability exiss in Subrion CMS 4.2.1 via modified code in a background field; when the information is modified, the data in it will be executed through eval().

  • CVE-2020-18326HigMar 4, 2022
    risk 0.57cvss 8.8epss 0.02

    Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.

  • CVE-2020-18155CriJul 14, 2021
    risk 0.57cvss 9.8epss 0.01

    SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection.

  • CVE-2019-7357HigNov 10, 2020
    risk 0.57cvss 8.8epss 0.01

    Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.

  • CVE-2018-21037HigMar 17, 2020
    risk 0.57cvss 8.8epss 0.01

    Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/edit/1 URI.

  • CVE-2017-6069HigMar 27, 2017
    risk 0.57cvss 8.8epss 0.01

    Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.

  • CVE-2017-6068HigMar 27, 2017
    risk 0.57cvss 8.8epss 0.01

    Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.

  • CVE-2017-6066HigMar 27, 2017
    risk 0.57cvss 8.8epss 0.01

    Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.

  • CVE-2017-6002HigMar 27, 2017
    risk 0.57cvss 8.8epss 0.00

    Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.

  • CVE-2017-5543CriJan 20, 2017
    risk 0.57cvss 9.8epss 0.02

    includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request.

  • CVE-2019-20390HigMay 15, 2020
    risk 0.53cvss 8.1epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server without a victim's knowledge, by enticing an authenticated user to visit an attacker's web page. The application fails to validate…

  • CVE-2020-12468HigApr 29, 2020
    risk 0.51cvss 7.8epss 0.01

    Subrion CMS 4.2.1 allows CSV injection via a phrase value within a language. This is related to phrases/add/ and languages/download/.

  • CVE-2017-18366HigApr 15, 2019
    risk 0.50cvss 8.8epss 0.01

    Subrion CMS 4.1.5 has CSRF in blog/delete/.

  • CVE-2017-15063HigOct 6, 2017
    risk 0.50cvss 8.8epss 0.01

    There are CSRF vulnerabilities in Subrion CMS 4.1.x through 4.1.5, and before 4.2.0, because of a logic error. Although there is functionality to detect CSRF, it is called too late in the ia.core.php code, allowing (for example) an attack against the query parameter to…

  • CVE-2018-19422HigNov 21, 2018
    risk 0.48cvss 7.2epss 0.64

    /panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these.

Page 1 of 4