SQL Injection Vulnerability in Subrion CMS by Intelliants
CVE-2024-25400
9.8CRITICAL
What is CVE-2024-25400?
Subrion CMS version 4.2.1 is reported to be vulnerable to an SQL Injection attack through the ia.core.mysqli.php file. This vulnerability arises due to improper handling of input within the application, which could potentially allow attackers to manipulate SQL queries. However, this issue has faced scrutiny and dispute from various security experts, raising questions about the actual exposure, as the relevant PHP file merely contains a class and reportedly lacks mechanisms to accept external input. The reported method's presence in the file has also been contested.