vendor:
Subrion CMS
by:
Aryan Chehreghani
8.8
CVSS
HIGH
Cross Site Request Forgery (CSRF)
352
CWE
Product Name: Subrion CMS
Affected Version From: 4.2.2001
Affected Version To: 4.2.2001
Patch Exists: NO
Related CWE:
CPE: a:subrion:subrion_cms
Platforms Tested: Windows 10
2022
Subrion CMS 4.2.1 – Cross Site Request Forgery (CSRF) (Add Amin)
A CSRF vulnerability was discovered in 4.2.1 version of Subrion CMS, which allows authorized users to be added to the system. An attacker can craft a malicious request to add an admin user to the system.
Mitigation:
Implementing a CSRF token in the application can prevent this type of attack.