Subrion

Subrion Cms

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.01%
  • Veröffentlicht 02.02.2026 23:16:02
  • Zuletzt bearbeitet 11.02.2026 20:33:17

Multiple reflected cross-site scripting (XSS) vulnerabilities in the installation module of Subrion CMS v4.2.1 allows attackers to execute arbitrary Javascript in the context of the user's browser via injecting a crafted payload into the dbuser, dbpw...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 11.09.2025 00:00:00
  • Zuletzt bearbeitet 25.11.2025 15:15:52

An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin panel - to gain escalated privileges in the context of the SQL query tool.

  • EPSS 0.25%
  • Veröffentlicht 27.02.2024 16:15:46
  • Zuletzt bearbeitet 27.03.2025 14:55:13

Subrion CMS 4.2.1 is vulnerable to Cross Site Scripting (XSS) via adminer.php.

Exploit
  • EPSS 0.49%
  • Veröffentlicht 27.02.2024 16:15:46
  • Zuletzt bearbeitet 23.05.2025 15:40:19

Subrion CMS 4.2.1 is vulnerable to SQL Injection via ia.core.mysqli.php. NOTE: this is disputed by multiple third parties because it refers to an HTTP request to a PHP file that only contains a class, without any mechanism for accepting external inpu...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 02.08.2018 00:29:00
  • Zuletzt bearbeitet 21.11.2024 03:49:53

Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas.

  • EPSS 0.2%
  • Veröffentlicht 02.08.2018 00:29:00
  • Zuletzt bearbeitet 21.11.2024 03:49:53

Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel.