在 Intelliants Subrion CMS 4.2.1 及更早版本中发现了一个安全弱点。该漏洞影响“登录页面”组件中的 front/login.php 文件内的 iaUsers::authorize 函数。对参数 $_SERVER['HTTP_REFERER'] 的操纵会导致开放重定向(open redirect)。此攻击可通过远程方式实施。相关利用代码已在公开渠道发布,可能被攻击者利用。厂商在披露初期已被联系,但始终未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Intelliants | Subrion CMS | 4.2.0 |
cpe:2.3:a:intelliants:subrion_cms:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet