CVE-2015-4129: SQL Injection
Published Jul 5, 2015
·Updated
SQL injection vulnerability in Subrion CMS before 3.3.3 allows remote authenticated users to execute arbitrary SQL commands via modified serialized data in a salt cookie.
Affected Software
1 affected component
Intelliants Subrion CMS<=3.3.2
Event History
Jul 5, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4129?
CVE-2015-4129 is considered a high severity vulnerability due to its potential for allowing remote authenticated users to execute arbitrary SQL commands.
2
How do I fix CVE-2015-4129?
To fix CVE-2015-4129, upgrade Subrion CMS to version 3.3.3 or later.
3
Who is affected by CVE-2015-4129?
CVE-2015-4129 affects users of Subrion CMS versions prior to 3.3.3.
4
What type of vulnerability is CVE-2015-4129?
CVE-2015-4129 is an SQL injection vulnerability.
5
Can CVE-2015-4129 be exploited remotely?
Yes, CVE-2015-4129 can be exploited remotely by authenticated users.