Vulnerabilities > Intelliants

DATE CVE VULNERABILITY TITLE RISK
2023-11-03 CVE-2023-46947 Code Injection vulnerability in Intelliants Subrion 4.2.1
Subrion 4.2.1 has a remote command execution vulnerability in the backend.
network
low complexity
intelliants CWE-94
8.8
2023-10-19 CVE-2023-43875 Cross-site Scripting vulnerability in Intelliants Subrion CMS 4.2.1
Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost, dbname, dbuser, adminusername and adminemail.
network
low complexity
intelliants CWE-79
6.1
2023-09-28 CVE-2023-43884 Cross-site Scripting vulnerability in Intelliants Subrion 4.2.1
A Cross-site scripting (XSS) vulnerability in Reference ID from the panel Transactions, of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into 'Reference ID' parameter.
network
low complexity
intelliants CWE-79
5.4
2023-09-27 CVE-2023-43828 Cross-site Scripting vulnerability in Intelliants Subrion 4.2.1
A Cross-site scripting (XSS) vulnerability in /panel/languages/ of Subrion v4.2.1 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into 'Title' parameter.
network
low complexity
intelliants CWE-79
5.4
2023-09-27 CVE-2023-43830 Cross-site Scripting vulnerability in Intelliants Subrion 4.2.1
A Cross-site scripting (XSS) vulnerability in /panel/configuration/financial/ of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into several fields: 'Minimum deposit', 'Maximum deposit' and/or 'Maximum balance'.
network
low complexity
intelliants CWE-79
5.4
2022-11-09 CVE-2022-43120 Cross-site Scripting vulnerability in Intelliants Subrion CMS 4.2.1
A cross-site scripting (XSS) vulnerability in the /panel/fields/add component of Intelliants Subrion CMS v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Field default value text field.
network
low complexity
intelliants CWE-79
6.1
2022-11-09 CVE-2022-43121 Cross-site Scripting vulnerability in Intelliants Subrion CMS 4.2.1
A cross-site scripting (XSS) vulnerability in the CMS Field Add page of Intelliants Subrion CMS v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tooltip text field.
network
low complexity
intelliants CWE-79
6.1
2022-08-29 CVE-2022-37059 Cross-site Scripting vulnerability in Intelliants Subrion CMS 4.2.1
Cross Site Scripting (XSS) in Admin Panel of Subrion CMS 4.2.1 allows attacker to inject arbitrary code via Login Field
network
low complexity
intelliants CWE-79
4.8
2022-06-11 CVE-2021-41502 Cross-site Scripting vulnerability in Intelliants Subrion CMS 4.2.1
An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execute malicious JavaScript code by modifying the name of the uploaded image, closing the html tag, or adding the onerror attribute.
network
low complexity
intelliants CWE-79
5.4
2022-04-29 CVE-2021-41948 Cross-site Scripting vulnerability in Intelliants Subrion
A cross-site scripting (XSS) vulnerability exists in the "contact us" plugin for Subrion CMS <= 4.2.1 version via "List of subjects".
network
low complexity
intelliants CWE-79
5.4