CVE-2017-5543: Code Injection
includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request.
Other sources
includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/intelliants/subrionto a version that resolves this vulnerability.Fixed in 4.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5543?
CVE-2017-5543 is classified as a high severity vulnerability due to its potential for remote PHP Object Injection attacks.
How do I fix CVE-2017-5543?
To fix CVE-2017-5543, upgrade Subrion CMS to version 4.1.0 or later.
What type of attack can CVE-2017-5543 facilitate?
CVE-2017-5543 can facilitate PHP Object Injection attacks through crafted serialized data in a salt cookie.
Which version of Subrion CMS is affected by CVE-2017-5543?
CVE-2017-5543 affects Subrion CMS version 4.0.5.
What component of Subrion CMS is vulnerable in CVE-2017-5543?
The vulnerable component in CVE-2017-5543 is includes/classes/ia.core.users.php.