{"id":"GHSA-rc94-7v55-wmg6","summary":"Subrion CMS CSRF Vulnerability","details":"There are CSRF vulnerabilities in Subrion CMS 4.1.x through 4.1.5, and before 4.2.0, because of a logic error. Although there is functionality to detect CSRF, it is called too late in the ia.core.php code, allowing (for example) an attack against the query parameter to panel/database.","aliases":["CVE-2017-15063"],"modified":"2024-02-16T08:21:51.946255Z","published":"2022-05-14T02:01:19Z","database_specific":{"github_reviewed_at":"2023-07-26T20:38:29Z","nvd_published_at":"2017-10-06T07:29:00Z","cwe_ids":["CWE-352"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-15063"},{"type":"WEB","url":"https://github.com/intelliants/subrion/issues/547"},{"type":"WEB","url":"https://github.com/intelliants/subrion/issues/570"},{"type":"WEB","url":"https://github.com/intelliants/subrion/commit/5fdf03af1a7d89c3692faa155e17457153020dca"},{"type":"WEB","url":"https://github.com/intelliants/subrion/commit/65fb937a588d730e57da0c2c5ca3bc4b9c2b5628"}],"affected":[{"package":{"name":"intelliants/subrion","ecosystem":"Packagist","purl":"pkg:composer/intelliants/subrion"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1"},{"fixed":"4.2.0"}]}],"versions":["v4.1.0","v4.1.1","v4.1.2","v4.1.3","v4.1.4","v4.1.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rc94-7v55-wmg6/GHSA-rc94-7v55-wmg6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}