First published: Fri Mar 04 2022(Updated: )
Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Intelliants Subrion CMS | =4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-18326.
The severity of CVE-2020-18326 is high.
Intelliants Subrion CMS version 4.2.1 is affected by CVE-2020-18326.
An attacker can exploit CVE-2020-18326 by sending an unauthorized request to the Victims by exploiting the Cross Site Request Forgery (CSRF) vulnerability in the Members administrator function.
To mitigate CVE-2020-18326, it is recommended to update Intelliants Subrion CMS to a version that is not affected by the vulnerability.