Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2020-35437

Disclosure Date: December 26, 2020 (last updated February 22, 2025)
Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI.
Attacker Value
Unknown

CVE-2019-7357

Disclosure Date: November 10, 2020 (last updated February 22, 2025)
Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.
Attacker Value
Unknown

CVE-2019-11406

Disclosure Date: May 08, 2019 (last updated November 27, 2024)
Subrion CMS 4.2.1 allows _core/en/contacts/ XSS via the name, email, or phone parameter.
0
Attacker Value
Unknown

CVE-2018-16631

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter.
0
Attacker Value
Unknown

CVE-2018-16629

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
0
Attacker Value
Unknown

CVE-2018-19422

Disclosure Date: November 21, 2018 (last updated November 27, 2024)
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these.
Attacker Value
Unknown

CVE-2018-14835

Disclosure Date: August 02, 2018 (last updated November 27, 2024)
Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas.
0
Attacker Value
Unknown

CVE-2018-14836

Disclosure Date: August 02, 2018 (last updated November 27, 2024)
Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel.
0