CVE-2017-6068: CSRF
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.
Other sources
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6068?
The severity of CVE-2017-6068 is considered to be medium due to potential Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) vulnerabilities.
How can I fix CVE-2017-6068?
To fix CVE-2017-6068, you should upgrade Subrion CMS to a version beyond 4.0.5 where this vulnerability has been addressed.
What systems are affected by CVE-2017-6068?
CVE-2017-6068 specifically affects Subrion CMS version 4.0.5.
Can CVE-2017-6068 lead to unauthorized content creation?
Yes, CVE-2017-6068 allows an attacker to create arbitrary blocks, which can be exploited to insert malicious content.
Is user action required to exploit CVE-2017-6068?
Exploitation of CVE-2017-6068 does not require user interaction, making it a critical concern for administrators.