CVE-2017-6002: XSS
Published Mar 27, 2017
·Updated
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.
Affected Software
1 affected component
Intelliants Subrion CMS=4.0.5.10
Event History
Mar 27, 2017
CVE Published
via MITRE·01:55 AM
Data Sourced
via MITRE·01:55 AM
Description
Data Sourced
via NVD·02:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6002?
CVE-2017-6002 is considered a high severity vulnerability due to its impact on the integrity of blog entries.
2
How do I fix CVE-2017-6002?
To fix CVE-2017-6002, update to a version of Subrion CMS that includes a patch for this CSRF vulnerability.
3
What specific vulnerability does CVE-2017-6002 exploit?
CVE-2017-6002 exploits a Cross-Site Request Forgery (CSRF) vulnerability in the admin/blog/add/ endpoint.
4
Can CVE-2017-6002 lead to XSS attacks?
Yes, CVE-2017-6002 allows attackers to insert Cross-Site Scripting (XSS) payloads into blog entries through the body parameter.
5
What versions of Subrion CMS are affected by CVE-2017-6002?
CVE-2017-6002 affects Subrion CMS version 4.0.5.10.