CVE-2017-15063: CSRF
Published Oct 6, 2017
·Updated
There are CSRF vulnerabilities in Subrion CMS 4.1.x through 4.1.5, and before 4.2.0, because of a logic error. Although there is functionality to detect CSRF, it is called too late in the ia.core.php code, allowing (for example) an attack against the query parameter to panel/database.
Affected Software
2 affected componentsFixes available
composer/intelliants/subrion>=4.1<4.2.0
4.2.0
Intelliants Subrion<=4.1.5
Remediation
Patch Available
Event History
Oct 6, 2017
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
May 14, 2022
Advisory Published
02:01 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-15063?
CVE-2017-15063 is considered a high severity vulnerability due to its potential for CSRF attacks.
2
How do I fix CVE-2017-15063?
To fix CVE-2017-15063, you should upgrade to Subrion CMS version 4.2.0 or later.
3
Which versions of Subrion CMS are affected by CVE-2017-15063?
CVE-2017-15063 affects Subrion CMS versions 4.1.x through 4.1.5, and all versions before 4.2.0.
4
What type of vulnerability is CVE-2017-15063?
CVE-2017-15063 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Is there a workaround for CVE-2017-15063?
There is no known workaround for CVE-2017-15063 other than upgrading to a patched version.