Lucene search

K
osvGoogleOSV:GHSA-Q4H5-G3W8-F9X7
HistoryMay 14, 2022 - 1:22 a.m.

Subrion CMS vulnerable to CSRF in admin/blocks/add

2022-05-1401:22:02
Google
osv.dev
4
subrion cms
csrf
vulnerability
admin blocks
xss

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

43.5%

Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

43.5%

Related for OSV:GHSA-Q4H5-G3W8-F9X7