← Back

Subrion

subrion

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Subrion Cms
subrion_cms

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Subrion
1Subrion Cms
Nov 21, 2024
Aug 2, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel.
1Subrion
1Subrion Cms
Nov 21, 2024
Aug 2, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas.