CVE-2017-6069: XSS
Published Mar 27, 2017
·Updated
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.
Affected Software
1 affected component
Intelliants Subrion CMS=4.0.5
Event History
Mar 27, 2017
CVE Published
via MITRE·01:55 AM
Data Sourced
via MITRE·01:55 AM
Description
Data Sourced
via NVD·02:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6069?
The severity of CVE-2017-6069 is rated as medium due to its potential impact on the application through CSRF.
2
How do I fix CVE-2017-6069?
To fix CVE-2017-6069, ensure to implement CSRF protection by validating tokens on state-changing requests in Subrion CMS.
3
What does CVE-2017-6069 exploit?
CVE-2017-6069 exploits a cross-site request forgery vulnerability in Subrion CMS allowing unauthorized tag additions.
4
Can CVE-2017-6069 lead to XSS attacks?
Yes, CVE-2017-6069 can lead to XSS attacks if the attacker successfully inserts scripts via the tags parameter.
5
Which version of Subrion CMS is affected by CVE-2017-6069?
CVE-2017-6069 affects Subrion CMS version 4.0.5.