Lucene search

K

Subrion Cms Security Vulnerabilities

cve
cve

CVE-2018-14835

Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas.

5.4CVSS

5.1AI Score

0.001EPSS

2018-08-02 12:29 AM
22
cve
cve

CVE-2018-14836

Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel.

6.5CVSS

6.4AI Score

0.001EPSS

2018-08-02 12:29 AM
20