First published: Mon Mar 27 2017(Updated: )
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Subrion CMS | =4.0.5.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6002 is considered a high severity vulnerability due to its impact on the integrity of blog entries.
To fix CVE-2017-6002, update to a version of Subrion CMS that includes a patch for this CSRF vulnerability.
CVE-2017-6002 exploits a Cross-Site Request Forgery (CSRF) vulnerability in the admin/blog/add/ endpoint.
Yes, CVE-2017-6002 allows attackers to insert Cross-Site Scripting (XSS) payloads into blog entries through the body parameter.
CVE-2017-6002 affects Subrion CMS version 4.0.5.10.