CSRF Vulnerability in Subrion CMS by Subrion
CVE-2017-6066
8.8HIGH
What is CVE-2017-6066?
The Subrion CMS version 4.0.5 is vulnerable to a Cross-Site Request Forgery (CSRF) attack due to improper validation in the admin languages editing functionality. Successful exploitation allows an attacker to execute unauthorized Edit Language actions, which can also lead to potential Cross-Site Scripting (XSS) vulnerabilities if malicious scripts are injected through the title parameter. This can severely impact the security and integrity of the application, permitting unauthorized changes without the consent of the admin user.