Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h8wv-vv58-468h

Опубликовано: 11 сент. 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Subrion CMS: Authenticated administrators are able to gain escalated access through Run SQL Query tool

An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin panel — to gain escalated privileges in the context of the SQL query tool.

Пакеты

Наименование

intelliants/subrion

composer
Затронутые версииВерсия исправления

<= 4.2.1

Отсутствует

EPSS

Процентиль: 16%
0.0005
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-566

Связанные уязвимости

CVSS3: 3.8
nvd
5 месяцев назад

An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin panel - to gain escalated privileges in the context of the SQL query tool.

EPSS

Процентиль: 16%
0.0005
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-566