Intelliants
Products
3- 65 CVEs
- 2 CVEs
- 2 CVEs
Recent CVEs
69| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-11444 | Cri | 0.65 | 9.8 | 0.13 | Jul 19, 2017 | Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array. | ||
| CVE-2024-25400 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2024 | Subrion CMS 4.2.1 is vulnerable to SQL Injection via ia.core.mysqli.php. NOTE: this is disputed by multiple third parties because it refers to an HTTP request to a PHP file that only contains a class, without any mechanism for accepting external input, and the reportedly… | ||
| CVE-2017-11445 | Cri | 0.64 | 9.8 | 0.01 | Jul 19, 2017 | Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array. | ||
| CVE-2017-6013 | Cri | 0.64 | 9.8 | 0.02 | Mar 27, 2017 | Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter. | ||
| CVE-2023-46947 | Hig | 0.57 | 8.8 | 0.01 | Nov 3, 2023 | Subrion 4.2.1 has a remote command execution vulnerability in the backend. | ||
| CVE-2021-43464 | Hig | 0.57 | 8.8 | 0.01 | Apr 4, 2022 | A Remiote Code Execution (RCE) vulnerability exiss in Subrion CMS 4.2.1 via modified code in a background field; when the information is modified, the data in it will be executed through eval(). | ||
| CVE-2020-18326 | Hig | 0.57 | 8.8 | 0.02 | Mar 4, 2022 | Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user. | ||
| CVE-2020-18155 | Cri | 0.57 | 9.8 | 0.01 | Jul 14, 2021 | SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection. | ||
| CVE-2019-7357 | Hig | 0.57 | 8.8 | 0.01 | Nov 10, 2020 | Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins. | ||
| CVE-2018-21037 | Hig | 0.57 | 8.8 | 0.01 | Mar 17, 2020 | Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/edit/1 URI. | ||
| CVE-2017-6069 | Hig | 0.57 | 8.8 | 0.01 | Mar 27, 2017 | Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter. | ||
| CVE-2017-6068 | Hig | 0.57 | 8.8 | 0.01 | Mar 27, 2017 | Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter. | ||
| CVE-2017-6066 | Hig | 0.57 | 8.8 | 0.01 | Mar 27, 2017 | Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter. | ||
| CVE-2017-6002 | Hig | 0.57 | 8.8 | 0.00 | Mar 27, 2017 | Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter. | ||
| CVE-2017-5543 | Cri | 0.57 | 9.8 | 0.02 | Jan 20, 2017 | includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request. | ||
| CVE-2019-20390 | Hig | 0.53 | 8.1 | 0.01 | May 15, 2020 | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server without a victim's knowledge, by enticing an authenticated user to visit an attacker's web page. The application fails to validate… | ||
| CVE-2020-12468 | Hig | 0.51 | 7.8 | 0.01 | Apr 29, 2020 | Subrion CMS 4.2.1 allows CSV injection via a phrase value within a language. This is related to phrases/add/ and languages/download/. | ||
| CVE-2017-18366 | Hig | 0.50 | 8.8 | 0.01 | Apr 15, 2019 | Subrion CMS 4.1.5 has CSRF in blog/delete/. | ||
| CVE-2017-15063 | Hig | 0.50 | 8.8 | 0.01 | Oct 6, 2017 | There are CSRF vulnerabilities in Subrion CMS 4.1.x through 4.1.5, and before 4.2.0, because of a logic error. Although there is functionality to detect CSRF, it is called too late in the ia.core.php code, allowing (for example) an attack against the query parameter to… | ||
| CVE-2018-19422 | Hig | 0.48 | 7.2 | 0.64 | Nov 21, 2018 | /panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these. |
- risk 0.65cvss 9.8epss 0.13
Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.
- risk 0.64cvss 9.8epss 0.01
Subrion CMS 4.2.1 is vulnerable to SQL Injection via ia.core.mysqli.php. NOTE: this is disputed by multiple third parties because it refers to an HTTP request to a PHP file that only contains a class, without any mechanism for accepting external input, and the reportedly…
- risk 0.64cvss 9.8epss 0.01
Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.
- risk 0.64cvss 9.8epss 0.02
Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.
- risk 0.57cvss 8.8epss 0.01
Subrion 4.2.1 has a remote command execution vulnerability in the backend.
- risk 0.57cvss 8.8epss 0.01
A Remiote Code Execution (RCE) vulnerability exiss in Subrion CMS 4.2.1 via modified code in a background field; when the information is modified, the data in it will be executed through eval().
- risk 0.57cvss 8.8epss 0.02
Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.
- risk 0.57cvss 9.8epss 0.01
SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection.
- risk 0.57cvss 8.8epss 0.01
Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.
- risk 0.57cvss 8.8epss 0.01
Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/edit/1 URI.
- risk 0.57cvss 8.8epss 0.01
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.
- risk 0.57cvss 8.8epss 0.01
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.
- risk 0.57cvss 8.8epss 0.01
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.
- risk 0.57cvss 8.8epss 0.00
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.
- risk 0.57cvss 9.8epss 0.02
includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request.
- risk 0.53cvss 8.1epss 0.01
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server without a victim's knowledge, by enticing an authenticated user to visit an attacker's web page. The application fails to validate…
- risk 0.51cvss 7.8epss 0.01
Subrion CMS 4.2.1 allows CSV injection via a phrase value within a language. This is related to phrases/add/ and languages/download/.
- risk 0.50cvss 8.8epss 0.01
Subrion CMS 4.1.5 has CSRF in blog/delete/.
- risk 0.50cvss 8.8epss 0.01
There are CSRF vulnerabilities in Subrion CMS 4.1.x through 4.1.5, and before 4.2.0, because of a logic error. Although there is functionality to detect CSRF, it is called too late in the ia.core.php code, allowing (for example) an attack against the query parameter to…
- risk 0.48cvss 7.2epss 0.64
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these.