github.comConfirmation
https://github.com/intelliants/subrion/issues/479 CVE-2017-11444
CRITICALNuclei
Subrion CMS <4.1.5.10 - SQL Injection
Record summary
CVE-2017-11444 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALSubrion CMS <4.1.5.10 - SQL InjectionCVSS 9.8
Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.
Impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation, or data leakage.
Remediation
Upgrade Subrion CMS to version 4.1.5.10 or later to mitigate this vulnerability.
WeaknessesCWE-89
Authorsdwisiswant0
Template tagscve2017cvesqlisubrionintelliantsvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:intelliants:subrion_cms:*:*:*:*:*:*:*:*
https://github.com/intelliants/subrion/issues/479 https://mp.weixin.qq.com/s/89mCnjUCvmptLsKaeVlC9Q https://nvd.nist.gov/vuln/detail/CVE-2017-11444 https://github.com/d4n-sec/d4n-sec.github.io https://github.com/qazbnm456/awesome-cve-poc
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-11444