First published: Wed Apr 29 2020(Updated: )
Subrion CMS 4.2.1 allows CSV injection via a phrase value within a language. This is related to phrases/add/ and languages/download/.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Intelliants Subrion | =4.2.1 | |
composer/intelliants/subrion | =4.2.1 | |
=4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12468 is a vulnerability in Subrion CMS 4.2.1 that allows CSV injection via a phrase value within a language.
CVE-2020-12468 has a severity rating of 7.8 (high).
CVE-2020-12468 affects Subrion CMS 4.2.1, allowing CSV injection via a phrase value within a language.
To fix CVE-2020-12468, you should update your Subrion CMS installation to version 4.2.2 or higher, which contains a patch for this vulnerability.
You can find more information about CVE-2020-12468 at the following reference: <a href='https://github.com/belong2yourself/vulnerabilities/tree/master/Subrion%20CMS/CSV%20Injection'>CVE-2020-12468 Reference</a>.