PT-2017-16876 · Subrion · Subrion Cms

Published

2017-03-27

·

Updated

2022-05-14

·

CVE-2017-6068

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Subrion CMS version 4.0.5
Description The issue allows an attacker to perform a CSRF attack on the "admin/blocks/add/" endpoint, enabling them to create any block. Additionally, the attacker can optionally insert XSS via the content parameter.
Recommendations For Subrion CMS version 4.0.5, as a temporary workaround, consider disabling access to the "admin/blocks/add/" endpoint until a patch is available. Restrict the use of the content parameter in this endpoint to minimize the risk of XSS insertion.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6068
GHSA-Q4H5-G3W8-F9X7

Affected Products

Subrion Cms