CSRF Vulnerability in Subrion CMS by Subrion
CVE-2017-6066

8.8HIGH

Key Information:

Vendor
CVE Published:
27 March 2017

What is CVE-2017-6066?

The Subrion CMS version 4.0.5 is vulnerable to a Cross-Site Request Forgery (CSRF) attack due to improper validation in the admin languages editing functionality. Successful exploitation allows an attacker to execute unauthorized Edit Language actions, which can also lead to potential Cross-Site Scripting (XSS) vulnerabilities if malicious scripts are injected through the title parameter. This can severely impact the security and integrity of the application, permitting unauthorized changes without the consent of the admin user.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.