Intelliants
Intelliants Subrion: vulnerabilidades y CVE
Intelliants Subrion tiene 25 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-25400 | Crítica (9.8) | 0.66% | — | 27 feb 2024 | Subrion CMS 4.2.1 is vulnerable to SQL Injection via ia.core.mysqli.php. NOTE: this is disputed by multiple third parties because it refers to an HTTP request to a PHP file that only contains a class, without any… |
| CVE-2023-46947 | Alta (8.8) | 1.3% | — | 3 nov 2023 | Subrion 4.2.1 has a remote command execution vulnerability in the backend. |
| CVE-2023-43884 | Media (5.4) | 0.46% | — | 28 sept 2023 | A Cross-site scripting (XSS) vulnerability in Reference ID from the panel Transactions, of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into 'Reference ID'… |
| CVE-2023-43830 | Media (5.4) | 0.59% | — | 27 sept 2023 | A Cross-site scripting (XSS) vulnerability in /panel/configuration/financial/ of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into several fields: 'Minimum… |
| CVE-2023-43828 | Media (5.4) | 0.59% | — | 27 sept 2023 | A Cross-site scripting (XSS) vulnerability in /panel/languages/ of Subrion v4.2.1 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into 'Title' parameter. |
| CVE-2021-41948 | Media (5.4) | 0.49% | — | 29 abr 2022 | A cross-site scripting (XSS) vulnerability exists in the "contact us" plugin for Subrion CMS <= 4.2.1 version via "List of subjects". |
| CVE-2020-22330 | Media (6.1) | 0.64% | — | 6 ago 2021 | Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page. |
| CVE-2020-18155 | Crítica (9.8) | 1.3% | — | 14 jul 2021 | SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection. |
| CVE-2020-23761 | Media (6.1) | 1.0% | — | 9 abr 2021 | Cross Site Scripting (XSS) vulnerability in subrion CMS Version <= 4.2.1 allows remote attackers to execute arbitrary web script via the "payment gateway" column on transactions tab. |
| CVE-2019-7356 | Media (5.4) | 0.75% | — | 4 nov 2020 | Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter. |
| CVE-2019-20390 | Alta (8.1) | 0.68% | — | 15 may 2020 | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server without a victim's knowledge, by enticing an authenticated user to visit… |
| CVE-2019-20389 | Media (6.1) | 0.95% | — | 15 may 2020 | An XSS issue was identified on the Subrion CMS 4.2.1 /panel/configuration/general settings page. A remote attacker can inject arbitrary JavaScript code in the v[language_switch] parameter (within multipart/form-data),… |
| CVE-2020-12469 | Media (6.5) | 0.86% | — | 29 abr 2020 | admin/blocks.php in Subrion CMS through 4.2.1 allows PHP Object Injection (with resultant file deletion) via serialized data in the subpages value within a block to blocks/edit. |
| CVE-2020-12468 | Alta (7.8) | 0.86% | — | 29 abr 2020 | Subrion CMS 4.2.1 allows CSV injection via a phrase value within a language. This is related to phrases/add/ and languages/download/. |
| CVE-2020-12467 | Media (6.5) | 0.94% | — | 29 abr 2020 | Subrion CMS 4.2.1 allows session fixation via an alphanumeric value in a session cookie. |
| CVE-2018-21037 | Alta (8.8) | 0.51% | — | 17 mar 2020 | Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/edit/1 URI. |
| CVE-2019-17225 | Media (5.4) | 1.9% | — | 6 oct 2019 | Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue. |
| CVE-2018-11317 | Media (6.1) | 0.91% | — | 3 jul 2019 | Subrion CMS before 4.1.4 has XSS. |
| CVE-2018-15563 | Media (6.1) | 0.69% | — | 2 oct 2018 | _core/admin/pages/add/ in Subrion CMS 4.2.1 has XSS via the titles[en] parameter. |
| CVE-2018-16327 | Media (4.8) | 0.62% | — | 1 sept 2018 | There is Stored XSS in Subrion 4.2.1 via the admin panel URL configuration. |
| CVE-2018-14840 | Media (6.1) | 3.7% | — | 2 ago 2018 | uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads). |
| CVE-2017-15063 | Alta (8.8) | 0.52% | — | 6 oct 2017 | There are CSRF vulnerabilities in Subrion CMS 4.1.x through 4.1.5, and before 4.2.0, because of a logic error. Although there is functionality to detect CSRF, it is called too late in the ia.core.php code, allowing (for… |
| CVE-2017-10795 | Media (6.1) | 1.1% | — | 2 jul 2017 | Cross-site scripting (XSS) vulnerability in Subrion CMS 4.1.4 allows remote attackers to inject arbitrary web script or HTML via the body to blog/add/, a different vulnerability than CVE-2017-6069. |
| CVE-2017-5543 | Crítica (9.8) | 2.0% | — | 20 ene 2017 | includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request. |
| CVE-2014-9120 | Media (4.3) | 0.99% | — | 10 dic 2014 | Cross-site scripting (XSS) vulnerability in Subrion CMS before 3.2.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to subrion/search/. |