Vulnerability Description
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server without a victim's knowledge, by enticing an authenticated user to visit an attacker's web page. The application fails to validate the CSRF token for a GET request. An attacker can craft a panel/uploads/read.json?cmd=rm URL (removing this token) and send it to the victim.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intelliants | Subrion | 4.2.1 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/157700/Subrion-CMS-4.2.1-Cross-Site-RequestExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/157700/Subrion-CMS-4.2.1-Cross-Site-RequestExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2019-20390?
CVE-2019-20390 is a vulnerability with a CVSS score of 8.1 (HIGH). A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server without a victim's knowledge, by enticing an authentic...
How severe is CVE-2019-20390?
CVE-2019-20390 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-20390?
Check the references section above for vendor advisories and patch information. Affected products include: Intelliants Subrion.