SQL Injection Vulnerability in Subrion CMS by Subrion
CVE-2017-6013
9.8CRITICAL
What is CVE-2017-6013?
Subrion CMS version 4.0.5.10 is susceptible to a SQL injection vulnerability in the admin/database section, specifically through the query parameter. This flaw can be exploited by attackers to execute unauthorized SQL commands, potentially compromising the backend database, leaking sensitive information, or altering database entries. Proper input validation and prepared statements are essential to mitigate this vulnerability.