Cross-Site Request Forgery in Subrion CMS Affects Administrator Password Management
CVE-2018-21037
8.8HIGH
What is CVE-2018-21037?
A security vulnerability exists in Subrion CMS versions 4.1.5 and potentially earlier, allowing attackers to exploit Cross-Site Request Forgery (CSRF) to change the administrator's password through unauthorized requests made to the panel/members/edit/1 URI. This could lead to unauthorized access and control over the CMS, posing significant risks to system integrity and data security.