Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Subrion_cms
(Intelliants)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 33 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2022-06-11 | CVE-2021-41502 | An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execute malicious JavaScript code by modifying the name of the uploaded image, closing the html tag, or adding the onerror attribute. | Subrion_cms | 5.4 | ||
2022-08-29 | CVE-2022-37059 | Cross Site Scripting (XSS) in Admin Panel of Subrion CMS 4.2.1 allows attacker to inject arbitrary code via Login Field | Subrion_cms | 4.8 | ||
2023-10-19 | CVE-2023-43875 | Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost, dbname, dbuser, adminusername and adminemail. | Subrion_cms | 6.1 | ||
2018-11-21 | CVE-2018-19422 | /panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these. | Subrion_cms | 7.2 | ||
2020-11-10 | CVE-2019-7357 | Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins. | Subrion_cms | 8.8 | ||
2019-05-08 | CVE-2019-11406 | Subrion CMS 4.2.1 allows _core/en/contacts/ XSS via the name, email, or phone parameter. | Subrion_cms | 6.1 | ||
2018-12-04 | CVE-2018-16631 | Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter. | Subrion_cms | 5.4 | ||
2018-12-04 | CVE-2018-16629 | panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element. | Subrion_cms | 4.8 | ||
2017-03-27 | CVE-2017-6069 | Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter. | Subrion_cms | 8.8 | ||
2017-03-27 | CVE-2017-6068 | Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter. | Subrion_cms | 8.8 |