Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ngpentest007

#18877of 53,633
14.2Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2020-11245
8.8
2020-11-10
Subrion · Subrion Cms · CVE-2019-7357
**Name of the Vulnerable Software and Affected Versions** Subrion CMS version 4.2.1 **Description** The issue concerns a CSRF vulnerability in the panel/modules/plugins/ endpoint. This allows an attacker to remotely activate or deactivate plugins. **Recommendations** For Subrion CMS version 4.2.1, consider disabling access to the `panel/modules/plugins/` endpoint until a patch is available to prevent remote activation or deactivation of plugins. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2020-11244
5.4
2020-11-04
Subrion · Subrion Cms · CVE-2019-7356
**Name of the Vulnerable Software and Affected Versions** Subrion CMS version 4.2.1 **Description** The issue allows for XSS via the `panel/phrases/` endpoint, specifically through the `VALUE` parameter. **Recommendations** For Subrion CMS version 4.2.1, update to a newer version that contains a fix for this issue.