PT-2019-15018 · Intelliants · Subrion
Hacker625
·
Published
2019-10-06
·
Updated
2019-10-08
·
CVE-2019-17225
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Subrion version 4.2.1
Description
The issue allows for XSS attacks through the
panel/members/ endpoint, specifically via the Username, Full Name, or Email fields. This is related to an "Admin Member JSON Update" issue.Recommendations
For Subrion version 4.2.1, update to a newer version that contains a fix for this issue. As a temporary workaround, consider restricting access to the
panel/members/ endpoint to minimize the risk of exploitation. Avoid using the Username, Full Name, or Email fields in this endpoint until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Subrion