Описание
Subrion CMS vulnerable to CSRF in admin/blocks/add
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.
Пакеты
Наименование
intelliants/subrion
composer
Затронутые версииВерсия исправления
<= 4.0.5
Отсутствует
Связанные уязвимости
CVSS3: 8.8
nvd
почти 9 лет назад
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.