Vulnerabilities > Subrion

DATE CVE VULNERABILITY TITLE RISK
2018-08-02 CVE-2018-14836 Improper Privilege Management vulnerability in Subrion CMS 4.2.1
Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel.
network
low complexity
subrion CWE-269
6.5
2018-08-02 CVE-2018-14835 Cross-site Scripting vulnerability in Subrion CMS 4.2.1
Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas.
network
low complexity
subrion CWE-79
5.4