Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2020-35437
Disclosure Date: December 26, 2020 (last updated February 22, 2025)
Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI.
0
Attacker Value
Unknown
CVE-2019-7357
Disclosure Date: November 10, 2020 (last updated February 22, 2025)
Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.
0
Attacker Value
Unknown
CVE-2019-11406
Disclosure Date: May 08, 2019 (last updated November 27, 2024)
Subrion CMS 4.2.1 allows _core/en/contacts/ XSS via the name, email, or phone parameter.
0
Attacker Value
Unknown
CVE-2018-16631
Disclosure Date: December 04, 2018 (last updated November 27, 2024)
Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter.
0
Attacker Value
Unknown
CVE-2018-16629
Disclosure Date: December 04, 2018 (last updated November 27, 2024)
panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
0
Attacker Value
Unknown
CVE-2018-19422
Disclosure Date: November 21, 2018 (last updated November 27, 2024)
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these.
0
Attacker Value
Unknown
CVE-2018-14835
Disclosure Date: August 02, 2018 (last updated November 27, 2024)
Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas.
0
Attacker Value
Unknown
CVE-2018-14836
Disclosure Date: August 02, 2018 (last updated November 27, 2024)
Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel.
0