First published: Mon Mar 27 2017(Updated: )
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Subrion CMS | =4.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-6069 is rated as medium due to its potential impact on the application through CSRF.
To fix CVE-2017-6069, ensure to implement CSRF protection by validating tokens on state-changing requests in Subrion CMS.
CVE-2017-6069 exploits a cross-site request forgery vulnerability in Subrion CMS allowing unauthorized tag additions.
Yes, CVE-2017-6069 can lead to XSS attacks if the attacker successfully inserts scripts via the tags parameter.
CVE-2017-6069 affects Subrion CMS version 4.0.5.