Vulnerabilities > Intelliants > Subrion > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-07-14 CVE-2020-18155 SQL Injection vulnerability in Intelliants Subrion 4.2.1
SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection.
network
low complexity
intelliants CWE-89
critical
9.8
2017-01-20 CVE-2017-5543 Code Injection vulnerability in Intelliants Subrion 4.0.5
includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request.
network
low complexity
intelliants CWE-94
critical
9.8