CVE-2017-6068 describes a Cross-Site Request Forgery (CSRF) vulnerability in Subrion CMS version 4.0.5, specifically within the admin/blocks/add/ functionality. This flaw allows an attacker to create arbitrary blocks, potentially injecting Cross-Site Scripting (XSS) via the content parameter, leading to high impact across confidentiality, integrity, and availability. With a CVSSv3 score of 8.8 (High), it requires user interaction but is network-exploitable with low attack complexity. While the vulnerability is significant, there is no evidence of active exploitation, publicly available exploit code, or notable community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0.5CPE matchmatch criteria | cpe:2.3:a:intelliants:subrion_cms:4.0.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.