vendor:
Subrion CMS
by:
Karthik R (3psil0nLambDa)
5.5
CVSS
MEDIUM
SQL Injection, Persistent XSS
79, 89
CWE
Product Name: Subrion CMS
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: Unknown
Related CWE:
CPE:
Platforms Tested: Unknown
Unknown
SUBRION CMS multiple vulnerabilities
There are multiple vulnerabilities in Subrion CMS. The first vulnerability allows attackers to bypass authentication and gain access to the admin panel using a specific username and password. The second vulnerability is a persistent XSS vulnerability in the title field of the Poll module and Manage pages. Attackers can inject malicious code into the title field, which will be executed when the page is viewed by other users. Additionally, other products like Auto Classifieds, Articles Script, Real estate script, and Web directory that run on the same CMS are also vulnerable.
Mitigation:
To mitigate the SQL Injection vulnerability, it is recommended to implement proper input validation and parameterized queries to prevent unauthorized access to the database. To mitigate the persistent XSS vulnerability, it is recommended to sanitize user input and encode special characters to prevent the execution of malicious code. Regularly updating Subrion CMS and its associated products is also advised.