SQL Injection Vulnerability in Subrion CMS by Intelliants
CVE-2024-25400

9.8CRITICAL

Key Information:

Vendor
CVE Published:
27 February 2024

What is CVE-2024-25400?

Subrion CMS version 4.2.1 is reported to be vulnerable to an SQL Injection attack through the ia.core.mysqli.php file. This vulnerability arises due to improper handling of input within the application, which could potentially allow attackers to manipulate SQL queries. However, this issue has faced scrutiny and dispute from various security experts, raising questions about the actual exposure, as the relevant PHP file merely contains a class and reportedly lacks mechanisms to accept external input. The reported method's presence in the file has also been contested.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.