Open Redirect Vulnerability in Intelliants Subrion CMS Affecting Login Page Functionality
CVE-2026-96773
Key Information:
- Vendor
Intelliants
- Status
- Vendor
- CVE Published:
- 24 September 2026
Badges
What is CVE-2026-96773?
A weakness has been discovered in Intelliants Subrion CMS version 4.2.1 and earlier, specifically within the login functionality found in the 'front/login.php' file. This flaw allows an attacker to manipulate the $_SERVER['HTTP_REFERER'] argument, leading to an open redirect scenario. Such an attack could be executed remotely, enabling malicious users to redirect unsuspecting visitors to potentially harmful sites. The exploit details have been made publicly available, and despite early notification attempts, Intelliants did not issue a response regarding this critical issue.
Affected Version(s)
Subrion CMS 4.2.0
Subrion CMS 4.2.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
