CVE-2012-4772

Subrion CMS <2.2.3 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in register/ in Subrion CMS before 2.2.3 allows remote attackers to execute arbitrary SQL commands via the plan_id parameter.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/22159

Scores

EPSS 0.0216
EPSS Percentile 84.4%

Details

CWE
CWE-89
Status published
Products (4)
intelliants/subrion_cms 2.0.4
intelliants/subrion_cms 2.2.0
intelliants/subrion_cms 2.2.1
intelliants/subrion_cms < 2.2.2
Published Oct 22, 2012
Tracked Since Feb 18, 2026