Show filters
33 Total Results
Displaying 11-20 of 33
Sort by:
Attacker Value
Unknown
CVE-2021-43464
Disclosure Date: April 04, 2022 (last updated October 07, 2023)
A Remiote Code Execution (RCE) vulnerability exiss in Subrion CMS 4.2.1 via modified code in a background field; when the information is modified, the data in it will be executed through eval().
0
Attacker Value
Unknown
CVE-2020-18326
Disclosure Date: March 04, 2022 (last updated October 07, 2023)
Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.
0
Attacker Value
Unknown
CVE-2020-18325
Disclosure Date: March 04, 2022 (last updated October 07, 2023)
Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.
0
Attacker Value
Unknown
CVE-2020-18324
Disclosure Date: March 04, 2022 (last updated October 07, 2023)
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.
0
Attacker Value
Unknown
CVE-2020-22330
Disclosure Date: August 06, 2021 (last updated February 23, 2025)
Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page.
0
Attacker Value
Unknown
CVE-2020-18155
Disclosure Date: July 14, 2021 (last updated February 23, 2025)
SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection.
0
Attacker Value
Unknown
CVE-2020-35437
Disclosure Date: December 26, 2020 (last updated February 22, 2025)
Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI.
0
Attacker Value
Unknown
CVE-2019-7357
Disclosure Date: November 10, 2020 (last updated February 22, 2025)
Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.
0
Attacker Value
Unknown
CVE-2019-7356
Disclosure Date: November 04, 2020 (last updated February 22, 2025)
Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter.
0
Attacker Value
Unknown
CVE-2019-20389
Disclosure Date: May 15, 2020 (last updated February 21, 2025)
An XSS issue was identified on the Subrion CMS 4.2.1 /panel/configuration/general settings page. A remote attacker can inject arbitrary JavaScript code in the v[language_switch] parameter (within multipart/form-data), which is reflected back within a user's browser without proper output encoding.
0