CVE-2020-18326: CSRF
Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-18326.
What is the severity of CVE-2020-18326?
The severity of CVE-2020-18326 is high.
Which software is affected by CVE-2020-18326?
Intelliants Subrion CMS version 4.2.1 is affected by CVE-2020-18326.
How can an attacker exploit CVE-2020-18326?
An attacker can exploit CVE-2020-18326 by sending an unauthorized request to the Victims by exploiting the Cross Site Request Forgery (CSRF) vulnerability in the Members administrator function.
How can I mitigate CVE-2020-18326?
To mitigate CVE-2020-18326, it is recommended to update Intelliants Subrion CMS to a version that is not affected by the vulnerability.