CVE-2018-19422 is a critical arbitrary file upload vulnerability affecting Subrion CMS version 4.2.1, specifically within the /panel/uploads directory. An authenticated attacker can bypass security restrictions by uploading malicious .pht or .phar files, which are not properly blocked by the .htaccess configuration. This allows for remote code execution (RCE) with a high impact on confidentiality, integrity, and availability, as reflected by its CVSS score of 7.2 (High) and a FAUCET Risk Score of 99/100. While not listed on CISA's KEV, public exploit modules exist in Metasploit and ExploitDB, indicating readily available attack tools, despite a lack of broader community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.2.1CPE matchmatch criteria | cpe:2.3:a:intelliants:subrion_cms:4.2.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.