RSS   Vulnerabilities for 'Subrion cms'   RSS

2018-08-01
 
CVE-2018-14840

CWE-79
 

 
uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads).

 
 
CVE-2018-14836

CWE-269
 

 
Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel.

 
 
CVE-2018-14835

CWE-79
 

 
Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas.

 

 >>> Vendor: Subrion 2 Products
CMS
Subrion cms


Copyright 2024, cxsecurity.com

 

Back to Top